Description
Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "message" parameter.
Remediation
References
Related Vulnerabilities
WordPress Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-14028)
WordPress Plugin NextCellent Gallery-NextGEN Legacy Cross-Site Scripting (1.9.17)
WordPress Plugin Export Post Info CSV Injection (1.2.0)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2019-16335)