CVE-2019-13397: XSS
Published Jul 9, 2019
·Updated
Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.
Affected Software
1 affected component
Enhancesoft osTicket=1.10.1
Event History
Jul 9, 2019
CVE Published
via MITRE·04:54 PM
Data Sourced
via MITRE·04:54 PM
Description
Frequently Asked Questions
1
What is CVE-2019-13397?
CVE-2019-13397 refers to an Unauthenticated Stored XSS vulnerability in osTicket 1.10.1.
2
How does CVE-2019-13397 work?
In osTicket 1.10.1, an attacker can inject arbitrary web script or HTML via arbitrary file extension while creating a support ticket, allowing them to gain admin privileges.
3
What is the severity of CVE-2019-13397?
The severity of CVE-2019-13397 has been rated as medium, with a severity value of 6.1.
4
Which software versions are affected by CVE-2019-13397?
osTicket 1.10.1 is the affected version by CVE-2019-13397.
5
How can I fix CVE-2019-13397?
Apply the latest security patch or upgrade to a fixed version of osTicket that addresses the Unauthenticated Stored XSS vulnerability.