CVE-2014-4744
osTicket <1.9.2 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in osTicket before 1.9.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Phone Number field to open.php or (2) Phone number field, (3) passwd1 field, (4) passwd2 field, or (5) do parameter to account.php.
Scores
EPSS
0.0026
EPSS Percentile
48.7%
Details
CWE
CWE-79
Status
published
Products (26)
enhancesoft/osticket
enhancesoft/osticket
enhancesoft/osticket
enhancesoft/osticket
enhancesoft/osticket
enhancesoft/osticket
enhancesoft/osticket
enhancesoft/osticket
enhancesoft/osticket
enhancesoft/osticket
... and 16 more
Published
Jul 09, 2014
Tracked Since
Feb 18, 2026