Description
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.
Remediation
References
Related Vulnerabilities
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-33327)
Oracle Database Server CVE-2012-1737 Vulnerability (CVE-2012-1737)
Internet Information Services Other Vulnerability (CVE-1999-1478)
PostgreSQL Insufficiently Protected Credentials Vulnerability (CVE-2021-23222)
WordPress Plugin WooCommerce Social Login PHP Object Injection (2.6.3)