Medium severity6.1NVD Advisory· Published Aug 30, 2020· Updated Jul 10, 2026
CVE-2020-24917
CVE-2020-24917
Description
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osTicket/osTicketdescription
Patches
Vulnerability mechanics
References
3- github.com/osTicket/osTicket/commit/518de223933eab0c5558741ce317f36958ef193dnvdPatchThird Party Advisory
- github.com/osTicket/osTicket/compare/v1.14.2...v1.14.3nvdRelease NotesThird Party Advisory
- sisl.lab.uic.edu/projects/chess/osticket-xss/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.