CVE-2020-22609: XSS
Published Jun 28, 2021
·Updated
Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php.
Affected Software
1 affected component
Enhancesoft osTicket<1.12.6
Remediation
Event History
Jun 28, 2021
CVE Published
via MITRE·06:38 PM
Data Sourced
via MITRE·06:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-22609?
CVE-2020-22609 is considered a medium severity vulnerability due to its potential for exploitation via Cross Site Scripting (XSS).
2
How do I fix CVE-2020-22609?
To fix CVE-2020-22609, upgrade your osTicket installation to version 1.12.6 or later.
3
What software is affected by CVE-2020-22609?
CVE-2020-22609 affects osTicket versions prior to 1.12.6.
4
What is the impact of CVE-2020-22609?
The impact of CVE-2020-22609 is that it allows an attacker to execute arbitrary JavaScript in the context of a user's session.
5
Is CVE-2020-22609 being actively exploited?
There have been no public reports of active exploitation of CVE-2020-22609, but it is recommended to patch the vulnerability as a precaution.