Cross-site scripting (XSS) vulnerability in the cryptography interface in Request Tracker (RT) before 4.2.12 allows remote attackers to inject arbitrary web script or HTML via a crafted public key.
| Software | From | Fixed in |
|---|---|---|
| bestpractical / request_tracker | - | 4.2.11.x |