Description
osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.
Remediation
References
Related Vulnerabilities
Moodle Improper Input Validation Vulnerability (CVE-2020-10738)
WordPress 4.6.x Possible SQL Injection Vulnerability (4.6 - 4.6.7)
Play Framework Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-12480)
MySQL CVE-2015-4756 Vulnerability (CVE-2015-4756)
Resin Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2969)