CVEs (45)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Nov 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning. |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Aug 30, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php. |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Aug 26, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call. |
scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent. |
include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name. |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Aug 7, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the appl...Show more |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Aug 7, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or un...Show more |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Aug 7, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) miti...Show more |
Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket. |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Apr 25, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because fi...Show more |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Mar 27, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" parameter. |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Mar 27, 2018 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access and guessing a 6-digit number. |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Mar 27, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Integer format vulnerability in the ticket number generator in Enhancesoft osTicket before 1.10.2 allows remote attackers to cause a denial-of-service (preventing the creation of new tickets) via a large number of digits...Show more |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Mar 27, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" parameter. |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Mar 27, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "message" parameter. |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Jan 23, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Jan 23, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter in a search action. |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Jul 9, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in osTicket before 1.9.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Phone Number field to open.php or (2) Phone number field, (3) passwd1...Show more |
2Enhancesoft Osticket2Osticket OsticketJul 10, 2026 Dec 30, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in osTicket 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to module.php, a different vector than CVE-2005-1439. NOTE: this issue has been...Show more |
Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message...Show more |