Best Practical RT
cpe:2.3:a:bestpractical:rt:*:*:*:*:*:*:*
- >= 5.0.0, < 5.0.10
- >= 6.0.0, < 6.0.3
A SQL injection vulnerability has been identified in Request Tracker (RT) versions 5.0.0 prior to 5.0.10 and 6.0.0 prior to 6.0.3. This vulnerability allows authenticated users to manipulate input that is directly included in database queries without adequate validation. As a result, there is a potential risk of unauthorized data access or modification within the RT database.
Exploitation of this vulnerability allows for SQL injection, where an authenticated user can interfere with database queries. This could lead to unauthorized data access or manipulation within the RT database.
Users can upgrade to RT versions 5.0.10 or 6.0.3. For those unable to upgrade immediately, it is recommended to restrict RT account access to trusted users.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.