NA

CVE-2019-147481

Vulnerability Summary

An issue exists in osTicket versions prior to 1.10.7 and 1.12.x prior to 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implemented for file content checks; also, the output is not handled properly, causing persistent XSS that leads to cookie stealing or malicious actions.

Vulnerability Trend

Exploits

An issue was discovered in osTicket versions before 1107 and 112x before 1121 The Ticket creation form allows users to upload files along with queries It was found that the file-upload functionality has fewer (or no) mitigations implemented for file content checks; also, the output is not handled properly, causing persistent XSS that leads ...