VulnerabilityModified
CVE-2019-14750
Stored XSS exists in setup/install.php.
MEDIUM 6.1EPSS 10.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 10.90% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- enhancesoft/osticket
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/154005/osTicket-1.12-Cross-Site-Scripting.htmlThird Party Advisory, VDB Entry
- https://github.com/osTicket/osTicket/commit/c3ba5b78261e07a883ad8fac28c214486c854e12Patch, Third Party Advisory
- https://github.com/osTicket/osTicket/releases/tag/v1.10.7Release Notes, Third Party Advisory
- https://github.com/osTicket/osTicket/releases/tag/v1.12.1Release Notes, Third Party Advisory
- https://www.exploit-db.com/exploits/47226Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/154005/osTicket-1.12-Cross-Site-Scripting.htmlThird Party Advisory, VDB Entry
- https://github.com/osTicket/osTicket/commit/c3ba5b78261e07a883ad8fac28c214486c854e12Patch, Third Party Advisory
- https://github.com/osTicket/osTicket/releases/tag/v1.10.7Release Notes, Third Party Advisory
- https://github.com/osTicket/osTicket/releases/tag/v1.12.1Release Notes, Third Party Advisory
- https://www.exploit-db.com/exploits/47226Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.