VYPR
Medium severity6.1NVD Advisory· Published Jul 9, 2019· Updated Jun 17, 2026

CVE-2019-13397

CVE-2019-13397

Description

Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.

Affected products

3
  • Osticket/Osticket2 versions
    cpe:2.3:a:enhancesoft:osticket:1.10.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:enhancesoft:osticket:1.10.1:*:*:*:*:*:*:*
    • (no CPE)range: 1.10.1
  • osTicket/osTicketdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.