The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute arbitrary code via a crafted saved search name.
References
Link | Resource |
---|---|
http://www.debian.org/security/2017/dsa-3882 | Third Party Advisory |
http://www.securityfocus.com/bid/99381 | Third Party Advisory VDB Entry |
https://forum.bestpractical.com/t/security-vulnerabilities-in-rt-2017-06-15/32016 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2017-07-03 16:29
Updated : 2024-02-04 19:29
NVD link : CVE-2017-5944
Mitre link : CVE-2017-5944
CVE.ORG link : CVE-2017-5944
JSON object : View
Products Affected
bestpractical
- request_tracker
CWE
CWE-20
Improper Input Validation