PT-2017-16777 · Best Practical Solutions · Request Tracker
Publicado
2017-06-15
·
Atualizado
2019-10-03
·
CVE-2017-5944
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Request Tracker versions 4.0.0 through 4.0.24
Request Tracker versions 4.2.0 through 4.2.13
Request Tracker versions 4.4.0 through 4.4.1
Description
The issue concerns the dashboard subscription interface in Request Tracker, which might allow remote authenticated users with certain privileges to execute arbitrary code via a crafted saved search name.
Recommendations
For versions 4.0.0 through 4.0.24, update to version 4.0.25 or later.
For versions 4.2.0 through 4.2.13, update to version 4.2.14 or later.
For versions 4.4.0 through 4.4.1, update to version 4.4.2 or later.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Request Tracker