peter bassill · operator
$ cve CVE-2019-14750 JSON

CVE-2019-14750 EXPLOIT

6.1
MEDIUM · CVSS 3.0 · EPSS 10.9% (pctl 96)

Patch early

A public exploit exists.

Description

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.

Scoring

CVSS6.1 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS10.9% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2019-08-07
Last modified2026-07-10

Affected (1)

VendorProduct
enhancesoftosticket

Public exploits

SourceTitleDate
exploit-dbosTicket 1.12 - Persistent Cross-Site Scripting2019-08-12

References

→ the Explorer  ·  watch your stack  ·  NVD