6.1
CVE-2026-38446
- EPSS 0.25%
- Veröffentlicht 03.08.2026 00:00:00
- Zuletzt bearbeitet 03.08.2026 20:17:22
- CVE-Watchlists
- Unerledigt
A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title is stored without adequate HTML escaping and later rendered in multiple staff-facing templates without proper output encoding. An attacker can inject arbitrary JavaScript by submitting a crafted ticket reply or email with a malicious subject line.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.161 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://github.com/osTicket/osTicket/blob/v1.18.3/include/staff/templates/thread-entry.tmpl.php#L84
https://github.com/osTicket/osTicket/blob/v1.18.3/include/staff/templates/thread-entries.tmpl.php
https://github.com/osTicket/osTicket/blob/v1.18.3/include/staff/templates/reply-expand.tmpl.php
https://github.com/fr3akhacks/cve-disclosures/blob/master/osTicket/CVE-2026-38446.md
https://github.com/osTicket/osTicket/commit/1e39bf1cf78fa298285f19b98f6a6dbb6808de19