Enhancesoft

Osticket

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.21%
  • Veröffentlicht 05.04.2023 22:15:07
  • Zuletzt bearbeitet 13.02.2025 17:15:40

Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.

Exploit
  • EPSS 0.62%
  • Veröffentlicht 10.03.2023 16:15:11
  • Zuletzt bearbeitet 21.11.2024 07:38:55

Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.

Exploit
  • EPSS 0.47%
  • Veröffentlicht 10.03.2023 16:15:10
  • Zuletzt bearbeitet 21.11.2024 07:38:54

Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.

Exploit
  • EPSS 1.02%
  • Veröffentlicht 10.03.2023 16:15:10
  • Zuletzt bearbeitet 21.11.2024 07:38:54

Cross-site Scripting (XSS) - Generic in GitHub repository osticket/osticket prior to v1.16.6.

Exploit
  • EPSS 1.02%
  • Veröffentlicht 10.03.2023 16:15:10
  • Zuletzt bearbeitet 21.11.2024 07:38:54

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

Exploit
  • EPSS 0.51%
  • Veröffentlicht 10.03.2023 16:15:10
  • Zuletzt bearbeitet 21.11.2024 07:38:54

Cross-site Scripting (XSS) - Stored in GitHub repository osticket/osticket prior to v1.16.6.

Exploit
  • EPSS 1.06%
  • Veröffentlicht 10.03.2023 16:15:10
  • Zuletzt bearbeitet 21.11.2024 07:38:54

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to v1.16.6.

Exploit
  • EPSS 0.67%
  • Veröffentlicht 02.12.2022 16:15:09
  • Zuletzt bearbeitet 21.11.2024 07:34:54

Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4.

  • EPSS 1.42%
  • Veröffentlicht 13.07.2022 16:15:08
  • Zuletzt bearbeitet 10.07.2026 18:20:35

A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web scripts or HTML via a crafted S...

  • EPSS 1%
  • Veröffentlicht 04.05.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:27:26

SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.