CVE detail
CVE-2019-13397 — CVE-2019-13397
Published 2019-07-09 · Modified 2026-06-17 · Vendor enhancesoft · Product osticket · Source nvd
MEDIUM
severity
CVSS-derived band
0.0111
EPSS probability
exploitation probability, 30d
63.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitrary file extension while creating a support ticket.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References