
Security fix for CVE-2025-9640 and CVE-2025-10230

Security fix for CVE-2025-9640 and CVE-2025-10230

New version 4.6.0

New version 4.6.0

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system, which could result in CSV injection via ticket values with special characters, or cross-site scripting via calendar invitations added to a ticket. For the oldstable distribution (bookworm), these problems have been

It was discovered that Request Tracker, an extensible trouble-ticket tracking system is prone to a CSV injection via ticket values with special characters that are exported to a TSV from search results. For the oldstable distribution (bookworm), this problem has been fixed in version 4.4.6+dfsg-1.1+deb12u3.
50 queries. 8.5 mb Memory usage. 0.252 seconds.