CVE-2019-14750

MEDIUM NUCLEI

Osticket < 1.10.7 - XSS

Title source: rule

Description

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Aishwarya Iyer · textwebappsphp
https://www.exploit-db.com/exploits/47226

Nuclei Templates (1)

osTicket < 1.12.1 - Cross-Site Scripting
MEDIUMby TenBird
Shodan: title:"osTicket" || http.title:"osticket" || http.html:"powered by osticket" || http.title:"osticket installer"
FOFA: title="osticket" || body="powered by osticket" || title="osticket installer"

Scores

CVSS v3 6.1
EPSS 0.0383
EPSS Percentile 88.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
osticket/osticket < 1.10.7
Published Aug 07, 2019
Tracked Since Feb 18, 2026