Description
A stored cross-site scripting (XSS) vulnerability in Enhancesoft osTicket v1.17.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Label input parameter when updating a custom list.
Remediation
References
Related Vulnerabilities
MySQL CVE-2020-14773 Vulnerability (CVE-2020-14773)
IBM RTC CVE-2018-1694 Vulnerability (CVE-2018-1694)
WordPress Plugin Vertical SlideShow 'upload.php' Arbitrary File Upload (2.1)
WebLogic Download of Code Without Integrity Check Vulnerability (CVE-2020-5398)
WordPress Plugin NewStatPress Multiple Vulnerabilities (0.9.8)