FixVibe

medium

Stored XSS in osTicket Installation Script (CVE-2019-14750)

osTicket releases before 1.10.7 and 1.12.x before 1.12.1 contain a stored cross-site scripting flaw in the installer workflow. FixVibe GitHub repo scans flag the affected installer source.

CVE-2019-14750CWE-79

Impact

CVE-2019-14750 affects osTicket releases before 1.10.7 and the 1.12.x line before 1.12.1 [S1]. An attacker who can complete the vulnerable installation workflow can store crafted administrator name data that executes in a user's browser after installation and login. The issue is stored cross-site scripting (CWE-79) with user interaction required; it can expose session data or enable actions in the affected user's browser context [S1].

Root Cause and Evidence

The affected installer persisted the administrator first-name and last-name values without the output-safe encoding added by the upstream fix. The maintainer-authored patch applies osTicket's HTML-character encoding before those values are stored [S2]. Official osTicket 1.10.7 and 1.12.1 release notes include that installer-form XSS correction in their security changes [S3] [S4].

Remediation

Upgrade the deployed application to osTicket 1.10.7, 1.12.1, or preferably a current supported release [S3] [S4]. Local forks should incorporate the upstream encoding fix for both administrator name fields [S2], rebuild from clean sources, and verify that the deployed artifact contains the corrected behavior. Remove the setup directory from production web roots after installation or deny web access to it. Review administrator sessions and relevant logs if a vulnerable installer was exposed.

How FixVibe covers it

FixVibe's authorized GitHub repository scans flag osTicket installer source associated with CVE-2019-14750, reported as a likely issue with the affected file and line.