Description
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2019-2484 Vulnerability (CVE-2019-2484)
WordPress Plugin WP?????? Cross-Site Scripting (1.3.9)
WordPress Plugin Super Simple Custom CSS Cross-Site Scripting (1.2)
ProjectSend Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2018-7201)
WordPress Plugin MouseWheel Smooth Scroll Cross-Site Request Forgery (5.6)