CVE-2023-41259: Bestpractical Request Tracker
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.
Affected products
- Bestpractical Request Tracker: before 4.4.7 (fixed in 4.4.7); from 5.0.0, before 5.0.5 (fixed in 5.0.5)
Published 2023-11-03. Last modified 2026-06-17.