CVE-2013-3373: Bestpractical Rt
Medium severity, CVSS 5.0. EPSS: 2.4% chance of exploitation in the next 30 days.
CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a MIME header.
Affected products
- Bestpractical Rt: version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; version 4.0.5 only; …
Published 2013-08-23. Last modified 2026-06-16.