An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-08-07T16:38:35

Updated: 2024-08-05T00:26:38.638Z

Reserved: 2019-08-07T00:00:00

Link: CVE-2019-14750

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-08-07T17:15:12.557

Modified: 2019-08-14T15:15:21.003

Link: CVE-2019-14750

cve-icon Redhat

No data.