Best Practical RT
cpe:2.3:a:bestpractical:rt:*:*:*:*:*:*:*
- >= 6.0.0, < 6.0.3
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Request Tracker (RT) versions 6.0.0 prior to 6.0.3. This vulnerability allows an attacker to induce a logged-in user to visit a malicious web page, which can then trigger arbitrary state-changing actions in RT on behalf of the user.
Exploitation of this vulnerability allows for Cross-Site Request Forgery, where an attacker can perform actions on behalf of a user without their consent.
Users are advised to upgrade to RT version 6.0.3, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.