Vulnerabilities > Enhancesoft > Osticket > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-06-28 | CVE-2020-22608 | Cross-site Scripting vulnerability in Enhancesoft Osticket Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php. | 6.1 |
2021-06-28 | CVE-2020-22609 | Cross-site Scripting vulnerability in Enhancesoft Osticket Cross Site Scripting (XSS) vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter in include/class.queue.php. | 6.1 |
2020-06-10 | CVE-2020-14012 | Cross-site Scripting vulnerability in Enhancesoft Osticket 1.14.2 scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. | 5.4 |
2020-05-04 | CVE-2020-12629 | Cross-site Scripting vulnerability in Enhancesoft Osticket include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name. | 5.4 |
2019-07-09 | CVE-2019-13397 | Cross-site Scripting vulnerability in Enhancesoft Osticket 1.10.1 Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket. | 6.1 |