Cross-Site Scripting Vulnerability in Request Tracker by Best Practical
CVE-2016-6127
6.1MEDIUM
What is CVE-2016-6127?
A Cross-Site Scripting (XSS) vulnerability exists in Request Tracker (RT) for versions 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2. This flaw arises when the AlwaysDownloadAttachments configuration setting is not enabled, allowing remote attackers to exploit file uploads. Attackers can inject arbitrary web scripts or HTML, potentially compromising user data and session integrity.
