Description
Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "sort" parameter.
Remediation
References
Related Vulnerabilities
Jetty Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-34429)
Nginx Use After Free Vulnerability (CVE-2022-32414)
Oracle JRE CVE-2023-22041 Vulnerability (CVE-2023-22041)
Oracle Database Server CVE-2022-21247 Vulnerability (CVE-2022-21247)
Oracle Application Server CVE-2004-1368 Vulnerability (CVE-2004-1368)