CVE-2013-3525 | Best Practical Request Tracker up to 3.8.14 Approvals ShowPending sql injection (ID 121245 / EDB-38459)
A vulnerability has been found in Best Practical Request Tracker up to 3.8.14 and classified as critical. This vulnerability affects unknown code of the file Approvals. The manipulation of the argument ShowPending leads to sql injection.
This vulnerability was named CVE-2013-3525. The attack can be initiated remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.