CVE-2017-15362
Dashboard / Vulnerabilities / CVE-2017-15362
CVE-2017-15362
Published: 16 Oct 2017Last Modified: 8 Jul 2026
Summary:
Details: osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link, aka XSS. Session ID and data theft may follow as well as the possibility of bypassing CSRF protections, injection of iframes to establish communication channels, etc. The vulnerability is present after login into the application. This affects a different tickets.php file than CVE-2015-1176.
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 9ae093da56c7d81f2b2d3fef0a8baa61f1e73cde
Fixed -None
Affected versions
1.10.1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
