S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 29, 2024

CVE-2019-14750 Scanner

CVE-2019-14750 scanner - Cross-Site Scripting (XSS) vulnerability in osTicket

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-14750
6.1
CVSS

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

osTicket is a popular open-source support ticket system that is widely used by organizations to manage customer support requests. With its user-friendly interface and customizable features, it serves as an effective platform for businesses to streamline their customer support operations. It provides a centralized place for businesses to manage all their customer support requests from different channels such as email, phone, and social media. The ticketing system also features automation tools, which helps to prioritize and streamline support requests to ensure prompt resolution.

Recently, a vulnerability in osTicket was detected which could cause significant damage if not fixed. The vulnerability with code CVE-2019-14750 was found in the setup/install.php file, which stores cross-site scripting (XSS) attacks. This vulnerability is caused by the lack of input sanitization provided in the firstname and lastname fields of the application. An attacker can insert malicious code in these fields that will automatically run and execute queries, leading to cookie stealing and other malicious actions.

When exploited, this vulnerability can lead to devastating consequences for businesses. An attacker can steal sensitive customer data, such as usernames, passwords, and other personal information, compromising the entire support ticket system. This can result in a loss of trust in the business and may affect the business's reputation negatively. The damage can even be extended to the customers, whose personal information may be exploited by malicious entities.

In conclusion, the osTicket vulnerability with code CVE-2019-14750 can lead to significant damages to businesses if not adequately addressed. But, with the pro features of the s4e.io platform, individuals can easily and quickly learn about vulnerabilities in their digital assets. The platform proactively scans the website and informs the user about possible vulnerabilities and threats. Get started with s4e.io to identify and protect against possible security vulnerabilities.

 

REFERENCES

Solution Advice

Luckily, there are a few precautions that can be taken to protect against this vulnerability. Here are some of the measures businesses can take to stay safe:

  • Update to the latest version: Keep your osTicket up-to-date with the latest version that patches the vulnerability.
  • Use security plugins: Implement a security plugin to prevent XSS attacks on your website by sanitizing user inputs.
  • Enable web application firewall: A firewall can help protect against SQL injection and other forms of attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-14750 scanner - Cross-Site Scripting (XSS) vulnerability in osTicket S4E