Description
scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent.
Remediation
References
Related Vulnerabilities
Atlassian Jira Uncontrolled Search Path Element Vulnerability (CVE-2019-20419)
WordPress 2.0.3 Multiple Unspecified Security Vulnerabilities (2.0 - 2.0.3)
WebLogic CVE-2021-2142 Vulnerability (CVE-2021-2142)
WordPress Plugin DELUCKS SEO Cross-Site Scripting (2.1.7)
PostgreSQL Integer Overflow or Wraparound Vulnerability (CVE-2023-5869)