Description
Cross-site scripting (XSS) vulnerability in client.inc.php in osTicket before 1.9.5.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP e-Commerce-Clockwork SMS Cross-Site Scripting (2.0.5)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Cross-Site Scripting (1.5.67)
WordPress Plugin Instinct e-Commerce Arbitrary File Upload (3.4)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Multiple Vulnerabilities (4.1.2)