{"id":"CVE-2015-1347","title":"Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.","summary":"Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.","severity":"medium","cvss":4.3,"cvssVector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","cwe":["CWE-79"],"vendor":"enhancesoft","product":"osticket","affected":["osticket <= 1.9.5"],"published":"2015-01-23","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2015-1347","references":[{"url":"https://github.com/osTicket/osTicket-1.8/commit/b38b3ca7235002137cc9ff74b3c24a4a78c9c2d1","label":"cve@mitre.org"},{"url":"https://github.com/osTicket/osTicket-1.8/releases/tag/v1.9.5.1","label":"cve@mitre.org"},{"url":"https://github.com/osTicket/osTicket-1.8/commit/b38b3ca7235002137cc9ff74b3c24a4a78c9c2d1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/osTicket/osTicket-1.8/releases/tag/v1.9.5.1","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01362,"epssPercentile":0.70116,"ingestedAt":"2026-07-10T19:05:51.153Z","slug":"CVE-2015-1347","body":"## Overview\n\nCross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.\n\n## Affected\n\n- `osticket <= 1.9.5`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}