CVE-2026-36214
MEDIUMosTicket 1.10-1.17.7 and 1.18.0-1.18.3 - Stored Cross-Site Scripting via Bootstrap Tooltip Component
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2026-36214. PoCs published by amnsecurity, WesWrench, HORKimhab.
AI-analyzed exploit summary This repository provides a detailed technical analysis and proof-of-concept for CVE-2026-36214, a stored XSS vulnerability in osTicket via Bootstrap Tooltip 3.3.4 (CVE-2019-8331). The exploit leverages unauthenticated file uploads and crafted HTML payloads to execute JavaScript in agent/admin sessions.
Description
osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip component and insufficient HTML sanitization, allowing remote attackers to execute arbitrary JavaScript in Agent or Admin sessions.
Exploits (3)
This repository provides a detailed technical analysis and proof-of-concept for CVE-2026-36214, a stored XSS vulnerability in osTicket via Bootstrap Tooltip 3.3.4 (CVE-2019-8331). The exploit leverages unauthenticated file uploads and crafted HTML payloads to execute JavaScript in agent/admin sessions.
This repository provides a detailed technical analysis of CVE-2026-36214, a stored XSS vulnerability in osTicket via a vulnerable Bootstrap Tooltip component (CVE-2019-8331). The writeup explains how unauthenticated users can upload malicious JavaScript files and craft payloads to execute arbitrary JavaScript in the context of authenticated Agents or Admins, bypassing HTML sanitization and CSP restrictions.
The repository contains no technical details or exploit code for CVE-2026-36214. Instead, it links to external GitHub repositories and encrypted archives, which is a common tactic for social engineering or malware distribution.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N