VYPR
Medium severity5.4NVD Advisory· Published Jul 13, 2022· Updated Jul 10, 2026

CVE-2022-32074

CVE-2022-32074

Description

A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Osticket/Osticket2 versions
    cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:*range: <2022-05-19
    • (no CPE)range: < a7842d494889fd5533d13deb3c6a7789768795ae
  • osTicket-plugins/Storage-FSdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.