Description Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6. Remediation References CVE-2023-1319 Related Vulnerabilities PHP Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2007-3294) MySQL CVE-2022-21611 Vulnerability (CVE-2022-21611) LimeSurvey Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2012-4994) WordPress Plugin WordPress Download Manager Unspecified Vulnerability (3.1.18) WordPress Plugin MiwoFTP-File & Folder Manager Arbitrary File Download (1.0.5) Severity Medium Classification CVE-2023-1319 CWE-707 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities