Article
Cyber News / Article / Vulnerability in Request Tracker software

CE
CERT Polska-2026-05-21
Vulnerability in Request Tracker software
CERT Polska during own research has found a vulnerability in Best Practical Request Tracker software and participated in coordination of its disclosure.
The vulnerabilityCVE-2026-6841: Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via thePageparameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victimâs browser.
This vulnerability affects versions from 5.0.4 up to 5.0.9 and from 6.0.0 up to 6.0.2.
The vulnerability was found by Aleksander Iwicki from CERT Polska.
Related articles
in
[email protected] (The Hacker News)Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
8 days ago
in
[email protected] (The Hacker News)Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
9 days ago
Io
Ionut ArghireSAP Patches Critical Extended Passport Processing Vulnerability
3 days ago
You might Also like

Gu
Guru Baran-2 days ago
Chrome 153 Fixes 230 Vulnerabilities, Including One 0-Day Exploited in the Wild

in
[email protected] (The Hacker News)-2 days ago
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

Gu
Guru Baran-2 days ago
