USN-8506-1: Request Tracker vulnerabilities | Ubuntu security notices
Aleksander Iwicki discovered that Request Tracker did not properly sanitizethe search “Page” URL parameter. A remote attacker could possibly use thisissue to conduct a reflected cross-site scripting attack. (CVE-2026-6841) It was discovered that Request Tracker did not properly sanitize user-controlled data written to spreadsheet exports of search results. A remoteattacker could possibly use this issue…