CVE-2025-30087: XSS
Published May 28, 2025
·Updated
Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.
Affected Software
3 affected components
Best Practical RT>=4.4<=4.4.7, >=5.0<=5.0.7
bestpractical Request Tracker>=4.4.0<4.4.8
bestpractical Request Tracker>=5.0.0<5.0.8
Event History
May 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-30087?
CVE-2025-30087 has been classified with a medium severity rating due to its potential impact on user sessions through XSS exploitation.
2
How do I fix CVE-2025-30087?
To mitigate CVE-2025-30087, upgrade your Best Practical RT to version 4.4.8 or 5.0.8 or later.
3
What types of attacks are enabled by CVE-2025-30087?
CVE-2025-30087 allows attackers to perform Cross-Site Scripting (XSS) via crafted parameters in a search URL.
4
Which versions of Best Practical RT are affected by CVE-2025-30087?
CVE-2025-30087 affects Best Practical RT versions 4.4 through 4.4.7 and 5.0 through 5.0.7.
5
What is Cross-Site Scripting in the context of CVE-2025-30087?
In the context of CVE-2025-30087, Cross-Site Scripting refers to the ability to inject malicious scripts into web pages viewed by other users.