CVE-2018-7192: XSS
Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "message" parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7192?
CVE-2018-7192 is a Cross-site scripting (XSS) vulnerability in Enhancesoft osTicket before 1.10.2.
What is the severity of CVE-2018-7192?
The severity of CVE-2018-7192 is medium with a CVSS score of 6.1.
How does CVE-2018-7192 affect osTicket?
CVE-2018-7192 allows remote attackers to inject arbitrary web script or HTML via the "message" parameter in the /ajax.php/form/help-topic endpoint in Enhancesoft osTicket before 1.10.2.
How can I fix CVE-2018-7192?
To fix CVE-2018-7192, it is recommended to upgrade to osTicket version 1.10.2 or newer.
Is there any additional information available about CVE-2018-7192?
Yes, you can find additional information about CVE-2018-7192 at the following reference: https://blog.securityevaluators.com/vulnerabilities-found-in-popular-ticketing-system-dd273bda229c