CVE-2020-22608: XSS
Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-22608?
CVE-2020-22608 is a Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6.
How does CVE-2020-22608 occur?
CVE-2020-22608 occurs when the queue-name parameter is not properly sanitized in the include/ajax.search.php file of Enhancesoft osTicket before v1.12.6.
What is the severity of CVE-2020-22608?
CVE-2020-22608 has a severity score of 6.1, which is considered medium.
How can I fix CVE-2020-22608?
To fix CVE-2020-22608, it is recommended to update Enhancesoft osTicket to version 1.12.6 or later.
Where can I find more information about CVE-2020-22608?
You can find more information about CVE-2020-22608 at the following link: [https://github.com/osTicket/osTicket/commit/d54cca0b265128f119b6c398575175cb10cf1754](https://github.com/osTicket/osTicket/commit/d54cca0b265128f119b6c398575175cb10cf1754).