CVE 5.1 MEDIUM

Reflected XSS in Request Tracker_CVE-2026-6841

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victimโ€™s browser.

This vulnerability affects versions from 5.0.4 up to 5.0.9 and from 6.0.0 up toย 6.0.2.

Basic Information

ID CVE-2026-6841
Source CERT-PL
Published May 21, 2026 at 11:49
Modified May 21, 2026 at 12:45

Affected Product

Vendor Best Practical
Product Request Tracker
Version 5.0.4
Affected Versions Best Practical Request Tracker 5.0.4
Best Practical Request Tracker 6.0.0

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.