CVE-2023-1318: Cross-site Scripting (XSS) - Generic in osticket/osticket
Published Mar 10, 2023
·Updated
Cross-site Scripting (XSS) - Generic in GitHub repository osticket/osticket prior to v1.16.6.
Affected Software
1 affected component
Enhancesoft osTicket<1.16.6
Remediation
Event History
Mar 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-1318?
CVE-2023-1318 is classified as a Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2023-1318?
To fix CVE-2023-1318, upgrade osTicket to version 1.16.6 or later.
3
What software is affected by CVE-2023-1318?
CVE-2023-1318 affects osTicket versions prior to 1.16.6.
4
What type of attack does CVE-2023-1318 allow?
CVE-2023-1318 allows attackers to execute arbitrary JavaScript in the context of the user's browser.
5
Is my osTicket installation safe from CVE-2023-1318?
If you are using osTicket version 1.16.6 or later, your installation is not vulnerable to CVE-2023-1318.