CVE-2023-1320: Cross-site Scripting (XSS) - Stored in osticket/osticket
Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-1320?
CVE-2023-1320 is a vulnerability that allows an attacker to inject malicious scripts into a website.
How does Cross-site Scripting (XSS) work?
Cross-site Scripting (XSS) occurs when a web application does not properly validate user input and allows an attacker to inject malicious scripts into web pages viewed by other users.
What is the severity of CVE-2023-1320?
CVE-2023-1320 has a severity score of 6.1, which is considered high.
How can I fix the Cross-site Scripting (XSS) vulnerability in osticket/osticket prior to v1.16.6?
To fix the Cross-site Scripting (XSS) vulnerability in osticket/osticket prior to v1.16.6, you should update to version 1.16.6 or later.
Where can I find more information about CVE-2023-1320?
You can find more information about CVE-2023-1320 in the following references: [GitHub Commit](https://github.com/osticket/osticket/commit/86f9693dc64ed54220ed6c10e13e824ca4f6aacf), [Huntr Bounties](https://huntr.dev/bounties/c2bb34ac-452d-4624-a1b9-c5b54f52f0cd).