Impact
RT is an open source, enterprise‑grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross‑Site Scripting vulnerability, where user‑controlled data is rendered without proper HTML escaping. An authenticated user with permission to set the relevant data can inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3.
Affected Systems
Best Practical RT versions 6.0.0 through 6.0.2 are vulnerable; the issue is resolved in RT 6.0.3 and later.
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate severity. The attack requires an authenticated user, so it is not remotely exploitable by unauthenticated actors. Exploitation probability is low, with an EPSS score of less than 1%, and the vulnerability is not listed in CISA KEV. The risk is consequently limited to environments where users have write access to the vulnerable fields.
OpenCVE Enrichment