Vulnerability Description
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bestpractical | Rt | 4.0.0 |
Related Weaknesses (CWE)
References
- http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.htmlPatch
- http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000227.htmlPatch
- http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000228.htmlPatch
- http://secunia.com/advisories/53505
- http://secunia.com/advisories/53522Vendor Advisory
- http://www.debian.org/security/2012/dsa-2670
- http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.htmlPatch
- http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000227.htmlPatch
- http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000228.htmlPatch
- http://secunia.com/advisories/53505
- http://secunia.com/advisories/53522Vendor Advisory
- http://www.debian.org/security/2012/dsa-2670
FAQ
What is CVE-2013-5587?
CVE-2013-5587 is a vulnerability with a CVSS score of 2.6 (LOW). Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket....
How severe is CVE-2013-5587?
CVE-2013-5587 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-5587?
Check the references section above for vendor advisories and patch information. Affected products include: Bestpractical Rt.