CVE-2018-7193: XSS
Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7193?
CVE-2018-7193 is a cross-site scripting (XSS) vulnerability in Enhancesoft osTicket before version 1.10.2.
How does CVE-2018-7193 impact osTicket?
CVE-2018-7193 allows remote attackers to inject arbitrary web script or HTML through the "order" parameter in /scp/directory.php.
What is the severity of CVE-2018-7193?
CVE-2018-7193 is classified as medium severity with a CVSS score of 6.1.
How can I fix CVE-2018-7193 in my osTicket installation?
To fix CVE-2018-7193, it is recommended to update your osTicket to version 1.10.2 or later, as the vulnerability has been patched in that version.
Where can I find more information about CVE-2018-7193?
More information about CVE-2018-7193 can be found at the following reference: https://blog.securityevaluators.com/vulnerabilities-found-in-popular-ticketing-system-dd273bda229c