Unauthenticated Stored XSS in osTicket by osTicket Inc.
CVE-2019-13397
6.1MEDIUM
What is CVE-2019-13397?
An unauthenticated stored Cross-Site Scripting (XSS) vulnerability in osTicket version 1.10.1 enables remote attackers to inject arbitrary web scripts or HTML code. This can occur when the attacker creates a support ticket using a specially crafted file extension, leading to potential unauthorized administrative access.
