Impact
RT includes a reflected Cross‑Site Scripting flaw that permits an attacker to prompt an authenticated RT user to visit a crafted URL, causing arbitrary JavaScript to run in the victim’s browser session. The flaw is present in versions 5.0.4 through 5.0.9 and 6.0.0 through 6.0.2 and was fixed in 5.0.10 and 6.0.3. Because the flaw is client‑side only, it does not compromise the RT server.
Affected Systems
The affected system is the Best Practical RT issue tracker. Vulnerable versions include RT 5.0.4 through 5.0.9 and RT 6.0.0 through 6.0.2. The vulnerability was fixed in RT 5.0.10 and RT 6.0.3.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score is <1%, suggesting a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated RT user to click a crafted URL; the flaw is reflected XSS and thus affects the victim’s browser session, potentially enabling session hijacking or execution of privileged actions in the user’s context. Because the vulnerability does not compromise the server itself, overall confidentiality, integrity, or availability risks for the RT instance remain low.
OpenCVE Enrichment
Debian DSA
Ubuntu USN