Cross-Site Scripting Vulnerability in Enhancesoft osTicket Software
CVE-2018-7192
6.1MEDIUM
What is CVE-2018-7192?
A Cross-Site Scripting (XSS) vulnerability has been identified in Enhancesoft osTicket prior to version 1.10.2. This security flaw enables remote attackers to inject arbitrary web scripts or HTML through the 'message' parameter in the /ajax.php/form/help-topic endpoint. Exploiting this vulnerability could lead to unauthorized actions and the disclosure of sensitive information, placing user accounts and data at risk.
