CVE-2013-5587
Publication date 23 August 2013
Last updated 24 July 2024
Ubuntu priority
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.
Status
Package | Ubuntu Release | Status |
---|---|---|
request-tracker3.8 | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
request-tracker4 | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
Notes
References
Other references
- http://www.debian.org/security/2013/dsa-2670
- http://secunia.com/advisories/53522
- http://secunia.com/advisories/53505
- http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000228.html
- http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000227.html
- http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.html
- https://www.cve.org/CVERecord?id=CVE-2013-5587