CyberRota Analysis
AI-GeneratedVersions 6.0.0 to 6.0.2 of the RT issue and ticket tracking system are vulnerable to a stored Cross-Site Scripting (XSS) flaw, allowing authenticated users to inject malicious JavaScript that executes in the context of other users. This could lead to unauthorized actions or data exposure when affected pages are viewed. Organizations using these versions should prioritize upgrading to 6.0.3 to mitigate potential security risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML escaping. An authenticated user with permission to set the relevant data can inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3.
Related CVEs
Other vulnerabilities affecting the same vendor(s)