The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute arbitrary code via a crafted saved search name.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-07-03T16:00:00

Updated: 2024-08-05T15:18:49.038Z

Reserved: 2017-02-09T00:00:00

Link: CVE-2017-5944

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-07-03T16:29:00.543

Modified: 2019-10-03T00:03:26.223

Link: CVE-2017-5944

cve-icon Redhat

No data.