Cross-Site Scripting Vulnerability in Best Practical RT Software
CVE-2025-31501
6.1MEDIUM
What is CVE-2025-31501?
The software is susceptible to cross-site scripting due to improper validation of input in RT permalinks, allowing attackers to inject malicious JavaScript. This can lead to unauthorized actions on behalf of users, compromise sensitive data, and create further security risks if not patched.
Affected Version(s)
RT 5.0.0 < 5.0.8
