CVE-2019-11537
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.php/users/import if an agent manager user uploads a crafted .csv file to the User Importer, because file contents can appear in an error message. The XSS can lead to local file inclusion.
- Affected products
- Osticket
- Enhancesoft Osticket
- < 1.12
- Fix
- Available
- CVSS 3.0
- 6.1 MEDIUM
- EPSS
- 4.6% (91th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2019-04-25
CVE-2019-11537 at NVD
1 known exploit for CVE-2019-11537
Proof-of-concept code and exploit modules indexed by Sploitus