Description
scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent.
Remediation
References
Related Vulnerabilities
WordPress Plugin Coditor-Code Editor Security Bypass (1.1)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-1551)
Squid Incorrect Conversion between Numeric Types Vulnerability (CVE-2023-46848)
WordPress Plugin My Category Order 'parentID' Parameter SQL Injection (2.8)