Description
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Filter Gallery Security Bypass (0.0.6)
PHP Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2022-31628)
WordPress Plugin Coming Soon Page & Maintenance Mode Cross-Site Scripting (1.8.1)
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-33333)