Best Practical Request Tracker
cpe:2.3:a:bestpractical:request_tracker:*:*:*:*:*:*:*
- < 4.4.9
- < 5.0.9
- < 6.0.2
A CSV injection vulnerability has been identified in Best Practical Request Tracker (RT) versions prior to 4.4.9, 5.0.9, and 6.0.2. This vulnerability allows malicious users to inject CSV-formatted data into ticket values, which can be exploited when the data is exported in TSV format.
Exploitation of this vulnerability could lead to CSV injection, where exported data is manipulated to execute unintended commands or scripts when opened in a spreadsheet application.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.