Cross-Site Scripting Vulnerability in osTicket by Enhancesoft
CVE-2018-7196
6.1MEDIUM
What is CVE-2018-7196?
A vulnerability exists in osTicket prior to version 1.10.2 that permits remote attackers to exploit the application through the 'sort' parameter in /scp/index.php. This security flaw allows the injection of arbitrary web scripts or HTML, potentially leading to unauthorized actions taken on behalf of users or the exposure of sensitive information.
