Логотип exploitDog
bind:CVE-2019-14750
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-14750

Количество 3

Количество 3

nvd логотип

CVE-2019-14750

больше 6 лет назад

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-wj9g-5wf3-5pxf

больше 3 лет назад

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2021-03847

больше 6 лет назад

Уязвимость компонента setup/install.php системы поддержки клиентов osTicket, позволяющая нарушителю осуществлять межсайтовые сценарные атаки

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-14750

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.

CVSS3: 6.1
3%
Низкий
больше 6 лет назад
github логотип
GHSA-wj9g-5wf3-5pxf

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.

CVSS3: 6.1
3%
Низкий
больше 3 лет назад
fstec логотип
BDU:2021-03847

Уязвимость компонента setup/install.php системы поддержки клиентов osTicket, позволяющая нарушителю осуществлять межсайтовые сценарные атаки

CVSS3: 6.1
3%
Низкий
больше 6 лет назад

Уязвимостей на страницу