Impact
The vulnerability allows an authenticated user with upload permissions to embed arbitrary JavaScript within an uploaded file. When that file is served inline rather than as a plain attachment, the JavaScript is executed in the browser context of any RT user who subsequently views or downloads it. This cross‑site scripting can lead to session hijacking, defacement, or theft of sensitive information, as the script runs with the privileges of the viewing user. This flaw existed in RT versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2, and has been patched in 5.0.10 and 6.0.3.
Affected Systems
The issue affects Bestpractical RT for both enterprise and open‑source editions. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 are vulnerable; the flaw is fixed in 5.0.10 and 6.0.3 and later releases.
Risk and Exploitability
With a CVSS score of 5.4 the vulnerability is considered moderate. The EPSS score of <1% indicates a low exploitation probability, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated victim with upload permissions, suggesting that compromised accounts or social engineering of trusted users are likely attack vectors. If such privileges are misused, the attack can affect all users who later view the uploaded content.
OpenCVE Enrichment
Debian DSA
Ubuntu USN