CVE-2023-27148: XSS
A stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Role Name parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-27148?
CVE-2023-27148 is a stored cross-site scripting (XSS) vulnerability in the Admin panel in Enhancesoft osTicket v1.17.2.
How does CVE-2023-27148 affect Enhancesoft osTicket?
CVE-2023-27148 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Role Name parameter in the Admin panel.
What is the severity of CVE-2023-27148?
The severity of CVE-2023-27148 is medium with a CVSS score of 4.8.
How can I fix CVE-2023-27148?
To fix CVE-2023-27148, upgrade to a version of Enhancesoft osTicket that is not affected by this vulnerability.
Where can I find more information about CVE-2023-27148?
You can find more information about CVE-2023-27148 at the following link: [CVE-2023-27148 - osTicket XSS Vulnerability](https://www.esecforte.com/cve-2023-27148-osticket_xss/)