CVE-2019-14750
MEDIUM NUCLEIOsticket < 1.10.7 - XSS
Title source: ruleDescription
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Aishwarya Iyer · textwebappsphp
https://www.exploit-db.com/exploits/47226
Nuclei Templates (1)
osTicket < 1.12.1 - Cross-Site Scripting
MEDIUMby TenBird
Shodan:
title:"osTicket" || http.title:"osticket" || http.html:"powered by osticket" || http.title:"osticket installer"
FOFA:
title="osticket" || body="powered by osticket" || title="osticket installer"
References (5)
Scores
CVSS v3
6.1
EPSS
0.0383
EPSS Percentile
88.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
osticket/osticket
< 1.10.7
Published
Aug 07, 2019
Tracked Since
Feb 18, 2026