CVE-2012-4733

Severity

60%

Complexity

68%

Confidentiality

106%

Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.

Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.

CVSS 2.0 Base Score 6. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:P).

Overview

Type

Best Practical Solutions RT

First reported 11 years ago

2013-08-23 16:55:00

Last updated 11 years ago

2013-08-27 17:16:00

Affected Software

Best Practical Solutions RT 4.0.0

4.0.0

Best Practical Solutions RT 4.0.0 Release Candidate 1

4.0.0

Best Practical Solutions RT 4.0.0 Release Candidate 2

4.0.0

Best Practical Solutions RT 4.0.0 Release Candidate 3

4.0.0

Best Practical Solutions RT 4.0.0 Release Candidate 4

4.0.0

Best Practical Solutions RT 4.0.0 Release Candidate 5

4.0.0

Best Practical Solutions RT 4.0.0 Release Candidate 6

4.0.0

Best Practical Solutions RT 4.0.0 Release Candidate 7

4.0.0

Best Practical Solutions RT 4.0.0 Release Candidate 8

4.0.0

Best Practical Solutions RT 4.0.1

4.0.1

Best Practical Solutions RT 4.0.1 release candidate 1

4.0.1

Best Practical Solutions RT 4.0.1 release candidate 2

4.0.1

Best Practical Solutions RT 4.0.2

4.0.2

Best Practical Solutions RT 4.0.2 release candidate 1

4.0.2

Best Practical Solutions RT 4.0.2 release candidate 2

4.0.2

Best Practical Solutions RT 4.0.3

4.0.3

Best Practical Solutions RT 4.0.10

4.0.10

Best Practical Solutions RT 4.0.11

4.0.11

Best Practical Solutions RT 4.0.12

4.0.12

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.