CVE-2020-14012: XSS
scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-14012?
CVE-2020-14012 is a vulnerability in osTicket 1.14.2 that allows XSS (Cross-Site Scripting) attacks via a Knowledgebase Category Name or Category Description.
How does CVE-2020-14012 affect osTicket?
CVE-2020-14012 affects osTicket 1.14.2 by allowing an attacker with Agent permissions to carry out XSS attacks through the Knowledgebase Category Name or Category Description fields.
What is the severity of CVE-2020-14012?
The severity of CVE-2020-14012 is medium with a CVSS score of 5.4.
How can an attacker exploit CVE-2020-14012?
An attacker with Agent permissions can exploit CVE-2020-14012 by injecting malicious code into the Knowledgebase Category Name or Category Description fields, which will be executed when viewed by other users.
Is there a fix available for CVE-2020-14012?
Yes, a fix is available for CVE-2020-14012. Users should update to a version of osTicket that includes the fix, such as version 1.14.3 or later.