CVE-2016-6127
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownloadAttachments config setting is not in use, allows remote attackers to inject arbitrary web script or…
Does this matter?
Lower severity and a low EPSS score (1.20%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownloadAttachments config setting is not in use, allows remote attackers to inject arbitrary web script or HTML via a file upload with an unspecified content type.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- bestpractical/request tracker
- Source
- cve@mitre.org
References
- http://www.debian.org/security/2017/dsa-3882Third Party Advisory
- http://www.securityfocus.com/bid/99375Third Party Advisory, VDB Entry
- https://forum.bestpractical.com/t/security-vulnerabilities-in-rt-2017-06-15/32016Vendor Advisory
- http://www.debian.org/security/2017/dsa-3882Third Party Advisory
- http://www.securityfocus.com/bid/99375Third Party Advisory, VDB Entry
- https://forum.bestpractical.com/t/security-vulnerabilities-in-rt-2017-06-15/32016Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.