CVE-2016-6127

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-6127
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-6127.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-6127
Downstream
Related
Published
2017-07-03T16:29:00Z
Modified
2025-04-20T01:37:25Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownloadAttachments config setting is not in use, allows remote attackers to inject arbitrary web script or HTML via a file upload with an unspecified content type.

References

Affected packages