CVE-2012-4731

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
11/11/2012
Last modified:
11/04/2025

Description

FAQ manager for Request Tracker (RTFM) before 2.4.5 does not properly check user rights, which allows remote authenticated users to create arbitrary articles in arbitrary classes via unknown vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bestpractical:rtfm:*:*:*:*:*:*:*:* 2.4.3 (including)
cpe:2.3:a:bestpractical:rtfm:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rtfm:2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rtfm:2.2.2:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rtfm:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rtfm:2.4.1:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rtfm:2.4.2:*:*:*:*:*:*:*