Vulnerabilities
Vulnerable Software
Enhancesoft:  Security Vulnerabilities
Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.
CVSS Score
6.1
EPSS Score
0.001
Published
2024-02-20
A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Role Name parameter.
CVSS Score
4.8
EPSS Score
0.001
Published
2023-10-23
A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a custom list.
CVSS Score
4.8
EPSS Score
0.001
Published
2023-10-23
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
CVSS Score
6.5
EPSS Score
0.624
Published
2023-09-08
A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop responding. When a long password is entered, this procedure will consume all available CPU and memory.
CVSS Score
7.5
EPSS Score
0.003
Published
2023-06-14
Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.
CVSS Score
8.8
EPSS Score
0.007
Published
2023-04-05
Cross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae.
CVSS Score
6.1
EPSS Score
0.003
Published
2023-04-05
SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function.
CVSS Score
9.8
EPSS Score
0.05
Published
2023-04-05
Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.
CVSS Score
7.1
EPSS Score
0.004
Published
2023-03-10
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.
CVSS Score
5.4
EPSS Score
0.31
Published
2023-03-10


Contact Us

Shodan ® - All rights reserved