{"api_version":"1","generated_at":"2026-07-23T15:00:17+00:00","cve":"CVE-2019-14750","urls":{"html":"https://cve.report/CVE-2019-14750","api":"https://cve.report/api/cve/CVE-2019-14750.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-14750","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-14750"},"summary":{"title":"CVE-2019-14750","description":"An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.","state":"PUBLISHED","assigner":"mitre","published_at":"2019-08-07 17:15:12","updated_at":"2026-07-10 18:20:35"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://github.com/osTicket/osTicket/commit/c3ba5b78261e07a883ad8fac28c214486c854e12","name":"https://github.com/osTicket/osTicket/commit/c3ba5b78261e07a883ad8fac28c214486c854e12","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"xss: Install Form · osTicket/osTicket@c3ba5b7 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/osTicket/osTicket/releases/tag/v1.12.1","name":"https://github.com/osTicket/osTicket/releases/tag/v1.12.1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Third Party Advisory"],"title":"Release v1.12.1 · osTicket/osTicket · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/47226","name":"https://www.exploit-db.com/exploits/47226","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"osTicket 1.12 - Persistent Cross-Site Scripting - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/154005/osTicket-1.12-Cross-Site-Scripting.html","name":"http://packetstormsecurity.com/files/154005/osTicket-1.12-Cross-Site-Scripting.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"osTicket 1.12 Cross Site Scripting ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/osTicket/osTicket/releases/tag/v1.10.7","name":"https://github.com/osTicket/osTicket/releases/tag/v1.10.7","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Third Party Advisory"],"title":"Release v1.10.7 · osTicket/osTicket · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-14750","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-14750","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"14750","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"enhancesoft","cpe5":"osticket","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T00:26:38.638Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/osTicket/osTicket/releases/tag/v1.12.1"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/osTicket/osTicket/releases/tag/v1.10.7"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/osTicket/osTicket/commit/c3ba5b78261e07a883ad8fac28c214486c854e12"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.com/files/154005/osTicket-1.12-Cross-Site-Scripting.html"},{"name":"47226","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/47226"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2019-08-13T13:33:06.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"https://github.com/osTicket/osTicket/releases/tag/v1.12.1"},{"tags":["x_refsource_MISC"],"url":"https://github.com/osTicket/osTicket/releases/tag/v1.10.7"},{"tags":["x_refsource_MISC"],"url":"https://github.com/osTicket/osTicket/commit/c3ba5b78261e07a883ad8fac28c214486c854e12"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.com/files/154005/osTicket-1.12-Cross-Site-Scripting.html"},{"name":"47226","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/47226"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-14750","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/osTicket/osTicket/releases/tag/v1.12.1","refsource":"MISC","url":"https://github.com/osTicket/osTicket/releases/tag/v1.12.1"},{"name":"https://github.com/osTicket/osTicket/releases/tag/v1.10.7","refsource":"MISC","url":"https://github.com/osTicket/osTicket/releases/tag/v1.10.7"},{"name":"https://github.com/osTicket/osTicket/commit/c3ba5b78261e07a883ad8fac28c214486c854e12","refsource":"MISC","url":"https://github.com/osTicket/osTicket/commit/c3ba5b78261e07a883ad8fac28c214486c854e12"},{"name":"http://packetstormsecurity.com/files/154005/osTicket-1.12-Cross-Site-Scripting.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/154005/osTicket-1.12-Cross-Site-Scripting.html"},{"name":"47226","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/47226"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2019-14750","datePublished":"2019-08-07T16:38:35.000Z","dateReserved":"2019-08-07T00:00:00.000Z","dateUpdated":"2024-08-05T00:26:38.638Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2019-08-07 17:15:12","lastModifiedDate":"2026-07-10 18:20:35","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:*","versionEndExcluding":"1.10.7","matchCriteriaId":"F4C67250-AA50-471C-9356-4C2DB0A3EA98"},{"vulnerable":true,"criteria":"cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:*","versionStartIncluding":"1.12","versionEndExcluding":"1.12.1","matchCriteriaId":"83439B7B-7744-4C7D-ABFB-BA2F3F8DEA5A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"14750","Ordinal":"1","Title":"CVE-2019-14750","CVE":"CVE-2019-14750","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"14750","Ordinal":"1","NoteData":"An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the firstname and lastname fields of the application. The insertion of malicious queries in those fields leads to the execution of those queries. This can further lead to cookie stealing or other malicious actions.","Type":"Description","Title":"CVE-2019-14750"},{"CveYear":"2019","CveId":"14750","Ordinal":"2","NoteData":"2019-08-07","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"14750","Ordinal":"3","NoteData":"2019-08-13","Type":"Other","Title":"Modified"}]}}}