{"id":"CVE-2015-1176","title":"Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter in a search action.","summary":"Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter in a search action.","severity":"medium","cvss":4.3,"cvssVector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","cwe":["CWE-79"],"vendor":"enhancesoft","product":"osticket","affected":["osticket <= 1.9.4"],"published":"2015-01-23","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2015-1176","references":[{"url":"http://packetstormsecurity.com/files/130057/osTicket-1.9.4-Cross-Site-Scripting.html","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/archive/1/534526/100/0/threaded","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/72276","label":"cve@mitre.org"},{"url":"https://github.com/osTicket/osTicket-1.8/pull/1639","label":"cve@mitre.org"},{"url":"https://github.com/osTicket/osTicket-1.8/releases/tag/v1.9.5","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/130057/osTicket-1.9.4-Cross-Site-Scripting.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/archive/1/534526/100/0/threaded","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/72276","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/osTicket/osTicket-1.8/pull/1639","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/osTicket/osTicket-1.8/releases/tag/v1.9.5","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01908,"epssPercentile":0.78584,"ingestedAt":"2026-07-10T19:05:51.149Z","slug":"CVE-2015-1176","body":"## Overview\n\nCross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter in a search action.\n\n## Affected\n\n- `osticket <= 1.9.4`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}