Skip to content
Noroxi

bestpractical records

73 published records for vendor bestpractical.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
7
With a fix record
83.6%
Median publish → KEV
No record has entered KEV

All records

73 records
  • CVE-2017-5944
    36Monitor

    The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remo

    HighCVSS 8.8No exploitEPSS 3%

    bestpractical · request trackerJul 3, 2017

  • Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.

    CriticalCVSS 9.1No exploitEPSS 1%

    bestpractical · request tracker for incident responseJul 14, 2022

  • Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.

    CriticalCVSS 9.1No exploitEPSS 1%

    bestpractical · request tracker for incident responseJul 14, 2022

  • RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint

    CriticalCVSS 9.1No exploitEPSS 0%

    bestpractical · request trackerJul 20, 2026

  • CVE-2017-5943
    35Monitor

    Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information

    HighCVSS 8.8No exploitEPSS 1%

    bestpractical · request trackerJul 3, 2017

  • CVE-2011-5092
    31Monitor

    Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges v

    HighCVSS 7.5No exploitEPSS 3%

    bestpractical · rtJun 4, 2012

  • CVE-2013-3525
    31Monitor

    SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL comman

    HighCVSS 7.5Proof of conceptEPSS 3%

    bestpractical · request trackerMay 10, 2013

  • The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorit

    HighCVSS 7.5No exploitEPSS 2%

    bestpractical · request trackerMar 21, 2019

  • Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a

    HighCVSS 7.5No exploitEPSS 2%

    bestpractical · request trackerOct 18, 2021

  • Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in

    HighCVSS 7.5No exploitEPSS 1%

    bestpractical · request trackerNov 3, 2023

  • Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API call

    HighCVSS 7.5No exploitEPSS 1%

    bestpractical · request trackerNov 3, 2023

  • Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.

    HighCVSS 7.5No exploitEPSS 1%

    bestpractical · request trackerNov 3, 2023

  • CVE-2014-9472
    29Monitor

    The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a den

    HighCVSS 7.1No exploitEPSS 3%

    debian · debian linuxMar 9, 2015

  • CVE-2011-4458
    28Monitor

    Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabl

    MediumCVSS 6.8No exploitEPSS 3%

    bestpractical · rtJun 4, 2012

  • CVE-2013-3370
    28Monitor

    Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which all

    MediumCVSS 6.8No exploitEPSS 2%

    bestpractical · rtAug 23, 2013

  • CVE-2011-5093
    27Monitor

    Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated u

    MediumCVSS 6.5No exploitEPSS 2%

    bestpractical · rtJun 4, 2012

  • CVE-2011-4460
    27Monitor

    SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users

    MediumCVSS 6.5No exploitEPSS 2%

    bestpractical · rtJun 4, 2012

  • CVE-2011-2085
    27Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote at

    MediumCVSS 6.8No exploitEPSS 1%

    bestpractical · rtJun 4, 2012

  • CVE-2012-4732
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other version

    MediumCVSS 6.8No exploitEPSS 1%

    bestpractical · rtNov 11, 2012

  • CVE-2015-1464
    26Monitor

    RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.

    MediumCVSS 6.4No exploitEPSS 2%

    fedoraproject · fedoraMar 9, 2015

  • CVE-2011-1686
    26Monitor

    Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc

    MediumCVSS 6.5No exploitEPSS 1%

    bestpractical · rtApr 22, 2011

  • CVE-2012-6579
    25Monitor

    Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encrypti

    MediumCVSS 6.4No exploitEPSS 1%

    bestpractical · request trackerJul 24, 2013

  • CVE-2009-3585
    24Monitor

    Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.

    MediumCVSS 5.8No exploitEPSS 3%

    bestpractical · rtDec 2, 2009

  • CVE-2009-4151
    24Monitor

    Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.

    MediumCVSS 5.8No exploitEPSS 2%

    bestpractical · rtDec 2, 2009

  • CVE-2012-4733
    24Monitor

    Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows

    MediumCVSS 6.0No exploitEPSS 2%

    bestpractical · rtAug 23, 2013