Vulnerabilities
Vulnerable Software
Enhancesoft:  >> Osticket  >> 1.17.2  Security Vulnerabilities
Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.
CVSS Score
6.1
EPSS Score
0.001
Published
2024-02-20
A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Role Name parameter.
CVSS Score
4.8
EPSS Score
0.001
Published
2023-10-23
A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a custom list.
CVSS Score
4.8
EPSS Score
0.001
Published
2023-10-23
A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop responding. When a long password is entered, this procedure will consume all available CPU and memory.
CVSS Score
7.5
EPSS Score
0.003
Published
2023-06-14


Contact Us

Shodan ® - All rights reserved