Unrated severityNVD Advisory· Published Aug 14, 2015· Updated May 6, 2026
CVE-2015-5475
CVE-2015-5475
Description
Multiple cross-site scripting (XSS) vulnerabilities in Request Tracker (RT) 4.x before 4.2.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) user and (2) group rights management pages.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- blog.bestpractical.com/2015/08/security-vulnerabilities-in-rt.htmlnvdPatchVendor Advisory
- bestpractical.com/release-notes/rt/4.2.12nvdPatchVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2015-August/164607.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2015-August/165124.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2015-August/165163.htmlnvd
- www.debian.org/security/2015/dsa-3335nvd
- www.securityfocus.com/bid/76364nvd
News mentions
0No linked articles in our index yet.