PT-2017-14022 · Osticket · Osticket
Publicado
2017-10-16
·
Atualizado
2017-11-07
·
CVE-2017-15362
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
osTicket version 1.10.1
Description
The issue allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link. This can lead to session ID and data theft, bypassing CSRF protections, and injection of iframes to establish communication channels. The issue is present after logging into the application.
Recommendations
For osTicket version 1.10.1, consider restricting access to the tickets.php file until a fix is available. As a temporary workaround, avoid using the status parameter in the support/scp/tickets.php link to minimize the risk of exploitation.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Osticket