CVE-2023-41260: Bestpractical Request Tracker

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.

Affected products

  • Bestpractical Request Tracker: before 4.4.7 (fixed in 4.4.7); from 5.0.0, before 5.0.5 (fixed in 5.0.5)

Published 2023-11-03. Last modified 2026-06-17.