4.3
CVSSv2

CVE-2014-4744

Published: 09/07/2014 Updated: 16/12/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in osTicket prior to 1.9.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) Phone Number field to open.php or (2) Phone number field, (3) passwd1 field, (4) passwd2 field, or (5) do parameter to account.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

enhancesoft osticket 1.8.4

osticket osticket

enhancesoft osticket 1.9.0

enhancesoft osticket 1.8.3

osticket osticket 1.0

osticket osticket 1.2.7

osticket osticket 1.3.0

osticket osticket 1.6

enhancesoft osticket 1.8.0.3

enhancesoft osticket 1.8.1

enhancesoft osticket 1.8.0.2

osticket osticket 1.8.1

osticket osticket 1.6.0

enhancesoft osticket 1.8.0.4

enhancesoft osticket 1.8.0

enhancesoft osticket 1.8.1.2

enhancesoft osticket 1.8.1.1

enhancesoft osticket 1.8.0.1