Description
Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.
Remediation
References
Related Vulnerabilities
WordPress Plugin Social Login Lite For WooCommerce Security Bypass (1.6.0)
WordPress Plugin Import all XML, CSV & TXT into WordPress Security Bypass (6.4.1)
PHP Out-of-bounds Read Vulnerability (CVE-2019-11050)
WordPress Plugin Quotes Collection Cross-Site Request Forgery (1.5.5.1)
Lighttpd Resource Management Errors Vulnerability (CVE-2012-5533)