Open Redirect Vulnerability in Best Practical Request Tracker Software
CVE-2022-25803

6.1MEDIUM

Key Information:

Vendor
CVE Published:
14 July 2022

What is CVE-2022-25803?

An open redirect vulnerability exists in Best Practical Request Tracker software prior to version 5.0.3, which allows attackers to redirect users to untrusted sites via maliciously crafted ticket search links. This weakness could be exploited to conduct phishing attacks or to impact user trust around the application, highlighting the importance of timely updates and security best practices.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.