Red Hat Bugzilla – Bug 1475068
CVE-2016-6127 rt: Cross-site scripting via malicious file upload
Last modified: 2017-07-25 21:36:50 EDT
It was discovered that Request Tracker is vulnerable to a cross-site scripting (XSS) attack if an attacker uploads a malicious file with a certain content type. Installations which use the AlwaysDownloadAttachments config setting are unaffected by this flaw. The applied fix addresses all existant and future uploaded attachments.
Created rt tracking bugs for this issue:
Affects: fedora-all [bug 1475084]