CVE-2020-24917: XSS
Published Aug 30, 2020
·Updated
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::uploadInlineImage() in include/ajax.draft.php.
Affected Software
2 affected components
osTicket osTicket<1.14.3
Enhancesoft osTicket<1.14.3
Remediation
Event History
Aug 30, 2020
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this osTicket vulnerability?
The vulnerability ID is CVE-2020-24917.
2
What is the severity of CVE-2020-24917?
The severity of CVE-2020-24917 is medium.
3
How does the vulnerability CVE-2020-24917 occur?
CVE-2020-24917 occurs through cross-site scripting (XSS) by exploiting a crafted filename.
4
What version of osTicket is affected by CVE-2020-24917?
osTicket version up to and excluding 1.14.3 is affected by CVE-2020-24917.
5
How can I fix CVE-2020-24917 in osTicket?
To fix CVE-2020-24917, you need to update osTicket to version 1.14.3 or later.