Description
Cross Site Scripting vulnerability in Enhancesoft osTicket before v1.12.6 via the queue-name parameter to include/ajax.search.php.
Remediation
References
Related Vulnerabilities
Ruby Numeric Errors Vulnerability (CVE-2008-2376)
Jetty Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-2080)
Oracle Database Server CVE-2014-2478 Vulnerability (CVE-2014-2478)
Ruby Other Vulnerability (CVE-2021-41817)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2019-17571)