影響
CVE-2019-14750 affects osTicket before 1.10.7 and 1.12.x before 1.12.1 [S1]. This stored XSS (CWE-79) requires user interaction [S1].
根本原因與證據
The installer stored administrator names without safe encoding; the upstream fix adds encoding [S2]. Release notes confirm the correction [S3] [S4].
修補方式
Upgrade to 1.10.7, 1.12.1, or a supported release [S3] [S4], apply the upstream fix [S2], and restrict installer access.
FixVibe 涵蓋範圍
Authorized GitHub scans identify source evidence as a high-confidence Likely issue. FixVibe does not submit forms, log in, render stored content, or execute JavaScript; repository evidence does not prove deployment or exploitability.
