{"id":"CVE-2020-24917","title":"osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.","summary":"osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"enhancesoft","product":"osticket","affected":["osticket < 1.14.3"],"patched":["osticket 1.14.3"],"published":"2020-08-30","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-24917","references":[{"url":"https://github.com/osTicket/osTicket/commit/518de223933eab0c5558741ce317f36958ef193d","label":"cve@mitre.org"},{"url":"https://github.com/osTicket/osTicket/compare/v1.14.2...v1.14.3","label":"cve@mitre.org"},{"url":"https://sisl.lab.uic.edu/projects/chess/osticket-xss/","label":"cve@mitre.org"},{"url":"https://github.com/osTicket/osTicket/commit/518de223933eab0c5558741ce317f36958ef193d","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/osTicket/osTicket/compare/v1.14.2...v1.14.3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://sisl.lab.uic.edu/projects/chess/osticket-xss/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01225,"epssPercentile":0.67523,"ingestedAt":"2026-07-10T19:05:51.236Z","slug":"CVE-2020-24917","body":"## Overview\n\nosTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.\n\n## Affected\n\n- `osticket < 1.14.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `osticket 1.14.3`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}