vendor:
osTicket
by:
Matthew Aberegg
5.5
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: osTicket
Affected Version From: osTicket 1.14.1
Affected Version To: osTicket 1.14.1
Patch Exists: YES
Related CWE:
CPE: a:osticket:osticket:1.14.1
Platforms Tested: CentOS 7
2020
osTicket 1.14.1 – ‘Saved Search’ Persistent Cross-Site Scripting
A persistent cross-site scripting vulnerability exists within the 'Saved Searches' functionality of osTicket.
Mitigation:
Apply the patch provided by the vendor.