Medium severity6.1NVD Advisory· Published Aug 7, 2019· Updated Jul 10, 2026
CVE-2019-14750
CVE-2019-14750
Description
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osTicket/osTicketdescription
Patches
Vulnerability mechanics
References
5- github.com/osTicket/osTicket/commit/c3ba5b78261e07a883ad8fac28c214486c854e12nvdPatchThird Party Advisory
- packetstormsecurity.com/files/154005/osTicket-1.12-Cross-Site-Scripting.htmlnvdThird Party AdvisoryVDB Entry
- github.com/osTicket/osTicket/releases/tag/v1.10.7nvdRelease NotesThird Party Advisory
- github.com/osTicket/osTicket/releases/tag/v1.12.1nvdRelease NotesThird Party Advisory
- www.exploit-db.com/exploits/47226nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.