Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.
References
Link | Resource |
---|---|
https://medium.com/@sarapremashish/osticket-1-10-1-unauthenticated-stored-xss-allows-an-attacker-to-gain-admin-privileges-6a0348761a3a | Exploit Third Party Advisory |
Configurations
Information
Published : 2019-07-09 10:15
Updated : 2019-07-10 05:35
NVD link : CVE-2019-13397
Mitre link : CVE-2019-13397
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
enhancesoft
- osticket