CVE-2019-11537: XSS
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can appear in an error message. The XSS can lead to local file inclusion.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of the XSS vulnerability in osTicket?
The vulnerability ID is CVE-2019-11537.
What is the severity level of CVE-2019-11537?
The severity level of CVE-2019-11537 is medium.
How does the XSS vulnerability in osTicket occur?
The XSS vulnerability in osTicket occurs when an agent manager user uploads a crafted .csv file to the User Importer.
How can the XSS vulnerability in osTicket lead to local file inclusion?
The XSS vulnerability in osTicket can lead to local file inclusion because the file contents can appear in an error message.
Are there any patches or updates available to fix CVE-2019-11537?
Yes, patches and updates are available to fix CVE-2019-11537. Please refer to the official osTicket releases and the provided GitHub links for more information.