CVE-2017-15362 Information
Feb 14, 2021
cve
Description
osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link aka XSS. Session ID and data theft may follow as well as the possibility of bypassing CSRF protections injection of iframes to establish communication channels etc. The vulnerability is present after login into the application. This affects a different tickets.php file than CVE-2015-1176.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://becomepentester.blogspot.ae/2017/10/osTicket-XSS-CVE-2017-15362.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: