The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which displays invitation data without HTML sanitization. XSS vulnerability allows an attacker to send a specifically crafted e-mail enabling JavaScript code execution by displaying the ticket in the context of the logged-in user.

This vulnerability affects versions from 5.0.4 through 5.0.8 and from 6.0.0 through 6.0.1.

Project Subscriptions

Vendors Products
Bestpractical Subscribe
Request Tracker Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-6031-1 request-tracker5 security update
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Bestpractical
Bestpractical request Tracker
Vendors & Products Bestpractical
Bestpractical request Tracker

Fri, 24 Oct 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Oct 2025 06:15:00 +0000

Type Values Removed Values Added
Description The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which displays invitation data without HTML sanitization. XSS vulnerability allows an attacker to send a specifically crafted e-mail enabling JavaScript code execution by displaying the ticket in the context of the logged-in user. This vulnerability affects versions from 5.0.4 through 5.0.8 and from 6.0.0 through 6.0.1.
Title Stored XSS in Request Tracker
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2025-10-24T16:55:03.802Z

Reserved: 2025-08-19T09:42:07.655Z

Link: CVE-2025-9158

cve-icon Vulnrichment

Updated: 2025-10-24T16:54:53.001Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-24T06:15:35.983

Modified: 2025-10-27T13:20:15.637

Link: CVE-2025-9158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-27T22:13:10Z

Weaknesses