https://bugzilla.redhat.com/show_bug.cgi?id=2503728

            Bug ID: 2503728
           Summary: CVE-2026-44228 rt: RT: Stored Cross-Site Scripting
                    vulnerability allows arbitrary code execution via
                    improper data handling. [fedora-all]
           Product: Fedora
           Version: rawhide
            Status: NEW
        Whiteboard: {"flaws": ["4804bc8e-ac37-437d-a15a-89339a41ed42"]}
         Component: rt
          Keywords: Security, SecurityTracking
          Severity: medium
          Priority: medium
          Assignee: [email protected]
          Reporter: [email protected]
        QA Contact: [email protected]
                CC: [email protected], [email protected],
                    [email protected],
                    [email protected]
            Blocks: 2502919
  Target Milestone: ---
    Classification: Fedora



Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.

RT is an open source, enterprise-grade issue and ticket tracking system.
Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting
(XSS) vulnerability, where user-controlled data is rendered without proper HTML
escaping. An authenticated user with permission to set the relevant data can
inject JavaScript that executes when another RT user views the affected page.
This issue has been fixed in version 6.0.3.


-- 
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2503728

Report this comment as SPAM: 
https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-spam&short_desc=Report%20of%20Bug%202503728%23c0

-- 
_______________________________________________
perl-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to