Skip to main content

Vendor/product archive

enhancesoft / osticket CVEs

Beta · best-effort

45 CVEs tagged to enhancesoft / osticket2 Critical, 9 High, 33 Medium, 1 Low, 0 Unrated.

CVE-2019-14750

Published Aug 7, 2019

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the…

CVSS 6.1 · Medium
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2019-14749

Published Aug 7, 2019

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are gen…

CVSS 8.8 · High
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2019-14748

Published Aug 7, 2019

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-up…

CVSS 5.4 · Medium
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2019-13397

Published Jul 9, 2019

Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creati…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11537

Published Apr 25, 2019

In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .…

CVSS 6.1 · Medium
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2018-7196

Published Mar 27, 2018

Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" para…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-7195

Published Mar 27, 2018

Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access and guessing a 6-di…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-7194

Published Mar 27, 2018

Integer format vulnerability in the ticket number generator in Enhancesoft osTicket before 1.10.2 allows remote attackers to cause a denial-of-service (preventing the creation of…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-7193

Published Mar 27, 2018

Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order"…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-7192

Published Mar 27, 2018

Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-1347

Published Jan 23, 2015

Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2015-1176

Published Jan 23, 2015

Cross-site scripting (XSS) vulnerability in upload/scp/tickets.php in osTicket before 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the status parameter…

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
25.9
Vendor/product tagsBeta · best-effort

CVE-2014-4744

Published Jul 9, 2014

Multiple cross-site scripting (XSS) vulnerabilities in osTicket before 1.9.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Phone Number field to open.p…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
25.6
Vendor/product tagsBeta · best-effort

CVE-2010-4634

Published Dec 30, 2010

Directory traversal vulnerability in osTicket 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to module.php, a different vector than C…

CVSS 5.0 · Medium
evidence mentions
5
Buzz score
27.4
Vendor/product tagsBeta · best-effort

CVE-2010-0606

Published Feb 11, 2010

Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f paramet…

CVSS 3.5 · Low
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2010-0605

Published Feb 11, 2010

SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the…

CVSS 7.5 · High
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2009-2361

Published Jul 8, 2009

SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.

CVSS 7.5 · High
evidence mentions
10
Buzz score
44.0
Vendor/product tagsBeta · best-effort

CVE-2006-5407

Published Oct 19, 2006

PHP remote file inclusion vulnerability in open_form.php in osTicket allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.

CVSS 7.5 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2005-1436

Published May 3, 2005

Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t parameter to view.php, (2) the osticket…

CVSS 6.8 · Medium
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2005-1439

Published May 3, 2005

Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file parameter.

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort
Showing 26-45 of 45 CVEsPage 2 of 2