First published: Thu Jul 14 2022(Updated: )
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bestpractical Request Tracker | <4.4.6 | |
Bestpractical Request Tracker | >=5.0.0<5.0.3 | |
ubuntu/request-tracker4 | <4.4.4+dfsg-2ubuntu1.23.04.1 | 4.4.4+dfsg-2ubuntu1.23.04.1 |
ubuntu/request-tracker4 | <4.4.6 | 4.4.6 |
ubuntu/request-tracker4 | <4.4.2-2ubuntu0.1~ | 4.4.2-2ubuntu0.1~ |
ubuntu/request-tracker4 | <4.4.3-2+ | 4.4.3-2+ |
ubuntu/request-tracker4 | <4.4.4+dfsg-2ubuntu1.22.04.1 | 4.4.4+dfsg-2ubuntu1.22.04.1 |
ubuntu/request-tracker4 | <4.4.4+dfsg-2ubuntu1.23.10.1 | 4.4.4+dfsg-2ubuntu1.23.10.1 |
debian/request-tracker4 | 4.4.3-2+deb10u2 4.4.3-2+deb10u3 4.4.4+dfsg-2+deb11u2 4.4.4+dfsg-2+deb11u3 4.4.6+dfsg-1.1+deb12u1 4.4.7+dfsg-1 | |
debian/request-tracker5 | 5.0.3+dfsg-3~deb12u2 5.0.5+dfsg-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25802 is a vulnerability in Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 that allows XSS (cross-site scripting) attacks via a crafted content type for an attachment.
CVE-2022-25802 has a severity rating of 6.1 (medium).
Best Practical Request Tracker (RT) versions before 4.4.6 and between 5.0.0 and 5.0.3 are affected by CVE-2022-25802.
To fix CVE-2022-25802, you should upgrade Best Practical Request Tracker (RT) to version 4.4.6 or 5.0.3 or later.
The CWE ID for CVE-2022-25802 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).