CVE-2023-46967: XSS
Published Feb 20, 2024
·Updated
Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.
Affected Software
2 affected components
Enhancesoft osTicket
Enhancesoft osTicket<1.18.0
Remediation
Event History
Feb 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-46967?
CVE-2023-46967 has a high severity rating due to its potential for privilege escalation via crafted support tickets.
2
How do I fix CVE-2023-46967?
To fix CVE-2023-46967, you should upgrade to the latest version of Enhancesoft osTicket that addresses this vulnerability.
3
What causes CVE-2023-46967?
CVE-2023-46967 is caused by inadequate sanitization in the sanitize function, allowing Cross Site Scripting vulnerabilities.
4
Who is affected by CVE-2023-46967?
CVE-2023-46967 affects users of Enhancesoft osTicket version 1.18.0 and possibly earlier versions.
5
Can CVE-2023-46967 be exploited remotely?
Yes, CVE-2023-46967 can be exploited remotely by attackers through crafted support tickets.