FixVibe

medium

<strong>XSS armazenado no instalador osTicket (CVE-2019-14750)</strong>

Versões antigas do osTicket contêm XSS armazenado. O FixVibe identifica evidências do GitHub com segurança.

CVE-2019-14750CWE-79

Impacto

CVE-2019-14750 affects osTicket before 1.10.7 and 1.12.x before 1.12.1 [S1]. This is stored XSS (CWE-79) requiring user interaction [S1].

Causa e evidências

The installer stored administrator names without safe encoding; the upstream fix adds encoding [S2]. Release notes confirm the correction [S3] [S4].

Correção

Upgrade to 1.10.7, 1.12.1, or a supported release [S3] [S4], and apply the upstream fix [S2].

Cobertura do FixVibe

Authorized GitHub scans report source evidence as Likely issue. FixVibe does not submit forms, log in, render content, or execute JavaScript; repository evidence does not prove deployment or exploitability.