CVE-2025-9158 MEDIUM

CVE-2025-9158: Stored XSS in Request Tracker

Vendor Best Practical
Product Request Tracker
Weakness CWE-79 · XSS
Published October 24, 2025
Last update October 24, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which displays invitation data without HTML sanitization. XSS vulnerability allows an attacker to send a specifically crafted e-mail enabling JavaScript code execution by displaying the ticket in the context of the logged-in user. This vulnerability affects versions from 5.0.4 through 5.0.8 and from 6.0.0 through 6.0.1.

Key dates

02Disclosure timeline

October 24, 2025 CVE published
October 24, 2025 Record updated

Related vulnerabilities

04Related CVE