CVE-2023-1317: Cross-site Scripting (XSS) - Reflected in osticket/osticket
Published Mar 10, 2023
·Updated
Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.
Affected Software
1 affected component
Enhancesoft osTicket<1.16.6
Remediation
Event History
Mar 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-1317?
CVE-2023-1317 is a Cross-site Scripting (XSS) vulnerability that exists in the GitHub repository osticket/osticket prior to version 1.16.6.
2
How severe is CVE-2023-1317?
CVE-2023-1317 has a severity value of 5.4, which is considered medium.
3
How does CVE-2023-1317 affect the osticket/osticket repository?
CVE-2023-1317 affects the osticket/osticket repository prior to version 1.16.6, allowing for reflected Cross-site Scripting (XSS) attacks.
4
How can I fix CVE-2023-1317?
To fix CVE-2023-1317, update osticket/osticket to version 1.16.6 or later.
5
What is the Common Weakness Enumeration (CWE) associated with CVE-2023-1317?
The Common Weakness Enumeration (CWE) associated with CVE-2023-1317 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').