CVE-2012-4733: Bestpractical Rt

Medium severity, CVSS 6.0. EPSS: 1.6% chance of exploitation in the next 30 days.

Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.

Affected products

  • Bestpractical Rt: version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.10 only; version 4.0.11 only; …

Published 2013-08-23. Last modified 2026-06-16.