CVE-2012-4734: Bestpractical Rt
Medium severity, CVSS 5.0. EPSS: 1.8% chance of exploitation in the next 30 days.
Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warning protection mechanism and cause victims to "modify arbitrary state" via unknown vectors related to a crafted link.
Affected products
- Bestpractical Rt: version 3.8.0 only; version 3.8.1 only; version 3.8.2 only; version 3.8.3 only; version 3.8.4 only; version 3.8.5 only; …
Published 2012-11-11. Last modified 2026-06-16.