CVE-2022-4271: Cross-site Scripting (XSS) - Reflected in osticket/osticket
Published Dec 2, 2022
·Updated
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4.
Affected Software
1 affected component
Enhancesoft osTicket<1.16.4
Remediation
Event History
Dec 2, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-4271?
CVE-2022-4271 is a vulnerability that allows attackers to inject and execute malicious scripts in the website viewed by users.
2
What is the severity of CVE-2022-4271?
CVE-2022-4271 has a severity value of 5.4, which is considered high.
3
How does CVE-2022-4271 affect osTicket?
CVE-2022-4271 affects osTicket versions prior to 1.16.4, allowing for cross-site scripting (XSS) attacks.
4
How can I fix CVE-2022-4271 in osTicket?
To fix CVE-2022-4271 in osTicket, you should update to version 1.16.4 or later.
5
What is the Common Weakness Enumeration (CWE) associated with CVE-2022-4271?
The Common Weakness Enumeration (CWE) associated with CVE-2022-4271 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').