Description
Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web script or HTML via the "order" parameter.
Remediation
References
Related Vulnerabilities
Joomla Improper Input Validation Vulnerability (CVE-2021-26036)
Oracle JRE CVE-2018-2629 Vulnerability (CVE-2018-2629)
WordPress Other Vulnerability (CVE-2007-3639)
MySQL CVE-2019-2686 Vulnerability (CVE-2019-2686)
WordPress URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-10100)