CVE-2019-14748Medium· 5.4▾ TwilightPoC availableAn issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implement…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.7 · likelihood 0.7 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.7%
2.7% → 3.6%
Exploit-DB (last check)
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implemented for file content checks; also, the output is not handled properly, causing persistent XSS that leads to cookie stealing or malicious actions. For example, a non-agent user can upload a .html file, and Content-Disposition will be set to inline instead of attachment.
osticket < 1.10.7osticket >= 1.12, < 1.12.1Upgrade past the affected range:
osticket 1.12.1Connected by shared product, vendor, weakness, or advisory.
CVE-2019-14750Medium· 6.1An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1
CVE-2019-14749High· 8.8An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1
CVE-2022-32074Medium· 5.4A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web scripts or HTML vi…
CVE-2019-11537Medium· 6.1In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can a…
CVE-2018-7196Medium· 6.1Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" parameter.
CVE-2018-7193Medium· 6.1Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" parameter.