Vulnerabilities > Enhancesoft > Osticket > 1.10.1

DATE CVE VULNERABILITY TITLE RISK
2020-05-04 CVE-2020-12629 Cross-site Scripting vulnerability in Enhancesoft Osticket
include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.
3.5
2019-07-09 CVE-2019-13397 Cross-site Scripting vulnerability in Enhancesoft Osticket 1.10.1
Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.
network
low complexity
enhancesoft CWE-79
6.1