Medium severity6.1NVD Advisory· Published Jul 14, 2022· Updated Jun 17, 2026
CVE-2022-25802
CVE-2022-25802
Description
Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Best Practical/Request Tracker (RT)description
- Range: <4.4.6 and <5.0.3
Patches
Vulnerability mechanics
References
3- docs.bestpractical.com/release-notes/rt/4.4.6nvdPatchRelease NotesVendor Advisory
- docs.bestpractical.com/release-notes/rt/5.0.3nvdPatchRelease NotesVendor Advisory
- docs.bestpractical.com/release-notes/rt/index.htmlnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.