VDB

CVE-2023-41259

CVE-2023-41259 PUBLISHED CVSS 7.5 HIGH

Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.

EPSS 0.14% · 33.2th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.14%
33.2th percentile

Affected Products

VendorProductVersions
best_practical_solutionsrequest_tracker0, 5x
n/an/an/a
bestpracticalrequest_tracker0, 5.0.0

Timeline

  • Nov 3, 2023 CVE Published
  • Nov 3, 2023 EPSS Score
  • Dec 4, 2023 EPSS Score
  • Jan 3, 2024 EPSS Score
  • Feb 3, 2024 EPSS Score
  • Mar 4, 2024 EPSS Score
  • Apr 4, 2024 EPSS Score
  • May 5, 2024 EPSS Score
  • Jun 4, 2024 EPSS Score
  • Jul 5, 2024 EPSS Score
  • Aug 4, 2024 EPSS Score
  • Sep 4, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›