JediKev
20 exploits
Active since Aug 2019
osTicket <1.10.7/1.12.x<1.12.1 - Unrestricted File Upload & Stored XSS via Ticket Form
CVSS 5.4
osTicket <1.10.7, <1.12.1 - Code Injection
CVSS 8.8
osTicket < 1.10.7 and 1.12.x < 1.12.1 - Stored Cross-Site Scripting in Installer Firstname/Lastname Fields
CVSS 6.1
osTicket < 1.14.2 - Stored Cross-Site Scripting via SLA Name
CVSS 5.4
osTicket < 1.14.3 - Server-Side Request Forgery
CVSS 9.8
osTicket-plugins - Storage-FS < 2022-05-19 - Stored Cross-Site Scripting via SVG File Upload
CVSS 5.4
osTicket audit_log < 2022-04-21 - Stored Cross-Site Scripting in auditlogs.tmpl.php
CVSS 6.1
osTicket-plugins audit_log < 2022-04-21 - SQL Injection via order Parameter in getOrder Function
CVSS 9.8
Enhancesoft osTicket 1.17.0-1.17.6 and 1.18.0-1.18.2 - Unauthenticated Arbitrary File Read via Ticket PDF Export
CVSS 7.5
osTicket < 1.12.6 - Cross-Site Scripting via Queue-Name Parameter
CVSS 6.1
osTicket < 1.12.6 - Cross-Site Scripting via Queue-Name Parameter
CVSS 6.1
osTicket < 1.14.3 - Cross-Site Scripting via Crafted Filename in DraftAjaxAPI
CVSS 6.1
osTicket < 1.16.4 - Reflected Cross-Site Scripting
CVSS 5.4
osTicket < 1.16.6 - Reflected Cross-Site Scripting
CVSS 5.4
osTicket < 1.16.6 - Stored Cross-Site Scripting
CVSS 5.4
osTicket < 1.16.6 - Reflected Cross-Site Scripting
CVSS 5.4
osTicket < 1.16.6 - Cross-Site Scripting
CVSS 5.4
osTicket < 1.16.6 - Stored Cross-Site Scripting
CVSS 4.8
osTicket < 1.16.6 - Stored Cross-Site Scripting
CVSS 6.1
osTicket < 1.17.6 - Broken Access Control in /scp/ajax.php
CVSS 5.4