Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL.
| Software | From | Fixed in |
|---|---|---|
| bestpractical / request_tracker | 4.4.0 | 4.4.8 |
| bestpractical / request_tracker | 5.0.0 | 5.0.8 |