CVE-2022-32074
A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.
- Affected products
- Osticket
- Enhancesoft Osticket
- < 2022-05-19
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 1.4% (71th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2022-07-13
CVE-2022-32074 at NVD
1 known exploit for CVE-2022-32074
Proof-of-concept code and exploit modules indexed by Sploitus