Article

    Cyber News / Article / Vulnerability in Request Tracker software

    Vulnerability in Request Tracker software
    CE
    CERT Polska-2026-05-21

    Vulnerability in Request Tracker software

    CERT Polska during own research has found a vulnerability in Best Practical Request Tracker software and participated in coordination of its disclosure.

    The vulnerabilityCVE-2026-6841: Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via thePageparameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victim’s browser.

    This vulnerability affects versions from 5.0.4 up to 5.0.9 and from 6.0.0 up to 6.0.2.

    The vulnerability was found by Aleksander Iwicki from CERT Polska.

    Original source