CVE-2012-4734: Bestpractical Rt

Medium severity, CVSS 5.0. EPSS: 1.8% chance of exploitation in the next 30 days.

Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warning protection mechanism and cause victims to "modify arbitrary state" via unknown vectors related to a crafted link.

Affected products

  • Bestpractical Rt: version 3.8.0 only; version 3.8.1 only; version 3.8.2 only; version 3.8.3 only; version 3.8.4 only; version 3.8.5 only; …

Published 2012-11-11. Last modified 2026-06-16.