Osticket · Osticket · CVE-2015-1176
**Name of the Vulnerable Software and Affected Versions**
osTicket versions prior to 1.9.5
**Description**
The issue is related to a cross-site scripting (XSS) vulnerability. This vulnerability allows remote attackers to inject arbitrary web script or HTML via the `status` parameter in a search action.
**Recommendations**
For versions prior to 1.9.5, update to version 1.9.5 or later to resolve the issue.