Server side cross-site scripting In request-tracker5
Description
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 5.0.3+dfsg-3~deb12u3 | ||
debian 13 | 5.0.7+dfsg-3 | ||
debian 14 | 5.0.7+dfsg-3 |
Aliases
1. 2. 3. 4. 5.