VYPR
Medium severity6.1NVD Advisory· Published Aug 7, 2019· Updated Jul 10, 2026

CVE-2019-14750

CVE-2019-14750

Description

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Osticket/Osticket2 versions
    cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:*range: <1.10.7
    • (no CPE)range: <1.10.7, <1.12.1
  • osTicket/osTicketdescription

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.