Description
Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/admin.php.
Remediation
References
Related Vulnerabilities
Magento Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2020-15151)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-3810)
Oracle Database Server CVE-2008-2608 Vulnerability (CVE-2008-2608)
WordPress Plugin WordPress Clean Up & Optimizer-Clean Up Optimizer SQL Injection (3.0.13)