MEDIUM
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1
Published Aug 7, 2019
5.4
MEDIUMCVSS 3.0
EPSS 2.73%
Description
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implemented for file content checks; also, the output is not handled properly, causing persistent XSS that leads to cookie stealing or malicious actions. For example, a non-agent user can upload a .html file, and Content-Disposition will be set to inline instead of attachment.
Affected products
No data.
OR
- < 1.10.7
- ≥ 1.12 · < 1.12.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- http://packetstormsecurity.com/files/154003/osTicket-1.12-File-Upload-Cross-Site-Scripting.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5888 Advisory
- https://github.com/osTicket/osTicket/commit/33ed106b1602f559a660a69f931a9d873685d1ba x_refsource_MISCPatchRelease NotesThird Party Advisory
- https://github.com/osTicket/osTicket/releases/tag/v1.10.7 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/osTicket/osTicket/releases/tag/v1.12.1 x_refsource_MISCThird Party Advisory
- https://www.exploit-db.com/exploits/47224 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/154003/osTicket-1.12-File-Upload-Cross-Site-Scripting.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5888 | Advisory | |
| https://github.com/osTicket/osTicket/commit/33ed106b1602f559a660a69f931a9d873685d1ba | x_refsource_MISCPatchRelease NotesThird Party Advisory | |
| https://github.com/osTicket/osTicket/releases/tag/v1.10.7 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/osTicket/osTicket/releases/tag/v1.12.1 | x_refsource_MISCThird Party Advisory | |
| https://www.exploit-db.com/exploits/47224 | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 7, 2019
Updated Aug 5, 2024
Reserved Aug 7, 2019
Link CVE-2019-14748
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-5888 Assigner mitre
Published Aug 7, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-5888