Skip to content

Latest commit

 

History

History

CVE-2019-14750

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 

CVE-2019-14750

This CVE can only be exploited when initially setting up the osTicket instance. The stored XSS occurs when the admin user is first created with a malicious payload (like <img src=x onerror=alert(1)>) in their firstname or lastname fields. Since this requires a brand-new osTicket instance with no setup, and the resulting user will be the admin anyways, there's no point in exploiting this CVE so I won't provide a relevant PoC.

Credits

Based on description found in Exploit-DB, "osTicket 1.12 - Persistent Cross-Site Scripting", located here by AISHWARYA IYER.