CVE-2013-3371
EPSS 0.44%Published: 8/23/2013Modified: 4/28/2026
Description
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 3.8.3 through 3.8.16 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via the filename of an attachment.
Affected packages (1)
- Debian/request-tracker4from 0, < 4.0.12-2