CVE-2013-3737: Bestpractical Request Tracker

Medium severity, CVSS 5.0. EPSS: 1.4% chance of exploitation in the next 30 days.

The MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13, when using the file-based session store (Apache::Session::File) and certain authentication extensions, allows remote attackers to reuse unauthorized sessions and obtain user preferences and caches via unspecified vectors.

Affected products

  • Bestpractical Request Tracker: version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; version 4.0.5 only; …

Published 2014-11-16. Last modified 2026-06-16.