CVE-2026-38444
MEDIUMosTicket 1.18.3 - Unauthenticated Stored Cross-Site Scripting via Email From Display Name
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-38444. PoCs published by fr3akhacks.
AI-analyzed exploit summary The repository contains detailed technical writeups for three osTicket vulnerabilities (CVE-2026-38444, CVE-2026-38446, CVE-2026-38447). The analysis includes root cause breakdowns, affected components, patch recommendations, and CVSS scoring, but no functional exploit code. Focuses on stored XSS via email headers/titles and weak API key generation.
Description
osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an unauthenticated attacker sends a reply email to an existing ticket from an unregistered address with an XSS payload in the From display name.
Exploits (1)
The repository contains detailed technical writeups for three osTicket vulnerabilities (CVE-2026-38444, CVE-2026-38446, CVE-2026-38447). The analysis includes root cause breakdowns, affected components, patch recommendations, and CVSS scoring, but no functional exploit code. Focuses on stored XSS via email headers/titles and weak API key generation.
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N