PT-2026-45153 · Rt+1 · Rt+1
CVE-2026-44229
·
Published
2026-05-20
·
Updated
2026-07-20
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
RT versions 5.0.0 through 5.0.9
RT versions 6.0.0 through 6.0.2
Description
An issue exists where uploaded content is served inline instead of as an attachment. An authenticated user with upload permissions can include JavaScript in the uploaded content, which then executes in the browser session of any user who views or downloads the file. This is a Cross-Site Scripting (XSS) flaw, which occurs when an application includes untrusted data in a web page without proper validation or escaping.
Recommendations
Update RT versions 5.0.0 through 5.0.9 to version 5.0.10.
Update RT versions 6.0.0 through 6.0.2 to version 6.0.3.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Rt