Best Practical Request Tracker
0 remedies
cpe:2.3:a:bestpractical:request_tracker:*:*:*:*:*:*:*
0 remedies
- >= 5.0.4, <= 5.0.8
- >= 6.0.0, <= 6.0.1
A stored cross-site scripting vulnerability has been identified in Best Practical Request Tracker versions 5.0.4 through 5.0.8 and 6.0.0 through 6.0.1. This vulnerability arises in the calendar invitation parsing feature, which displays invitation data without proper HTML sanitization. As a result, an attacker can send a specially crafted email that executes JavaScript code by displaying the ticket in the context of the logged-in user.
Exploitation of this vulnerability allows for the execution of malicious JavaScript in the context of the affected user.