CVE-2020-16193
26.08.2020, 12:15
osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.
| Vendor | Product | Version |
|---|---|---|
| osticket | osticket | 𝑥 < 1.14.3 |
𝑥
= Vulnerable software versions
References
osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.
| Vendor | Product | Version |
|---|---|---|
| osticket | osticket | 𝑥 < 1.14.3 |