CVE-2023-27149: XSS
Published Oct 23, 2023
·Updated
A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a custom list.
Affected Software
1 affected component
Enhancesoft osTicket=1.17.2
Event History
Oct 23, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-27149?
CVE-2023-27149 is a stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2.
2
How does CVE-2023-27149 affect Enhancesoft osTicket?
CVE-2023-27149 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a custom list.
3
What is the severity of CVE-2023-27149?
CVE-2023-27149 has a severity rating of medium (4.8).
4
How can I fix CVE-2023-27149 in Enhancesoft osTicket?
To fix CVE-2023-27149, update Enhancesoft osTicket to version 1.17.3 or later.
5
Where can I find more information about CVE-2023-27149?
More information about CVE-2023-27149 can be found at https://www.esecforte.com/cve-2023-27149-osticket_xss/