Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-5587

Опубликовано: 23 авг. 2013
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
request-tracker3.8not-affectedpackage
request-tracker4fixed4.0.12-2package

Примечания

  • This is covered by the patches applied for CVE-2013-3371 in DSA-2760 and DSA-2761.

  • NVD explicitly mentions CVE-2013-5587 only for the RT 4.x series.

  • patch for 3.8.17: https://github.com/bestpractical/rt/compare/rt-3.8.16...rt-3.8.17

  • patch for 4.0.13: https://github.com/bestpractical/rt/compare/rt-4.0.12...rt-4.0.13

  • still not clear why the split was done, but confirmed by upstream that this issue

  • is covered by the fixes applied for CVE-2013-3371

EPSS

Процентиль: 60%
0.00407
Низкий

Связанные уязвимости

ubuntu
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.

nvd
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.

github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.

EPSS

Процентиль: 60%
0.00407
Низкий