Cross-Site Scripting Vulnerability in Request Tracker's MobileUI Extension
CVE-2013-3736

Currently unrated

Key Information:

Vendor
CVE Published:
5 May 2014

What is CVE-2013-3736?

A cross-site scripting (XSS) vulnerability exists in the MobileUI extension for Request Tracker, allowing remote attackers to inject arbitrary web scripts or HTML if they can manipulate the name of an attached file. This could potentially lead to malicious actions performed under the context of the user's session.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.