{"id":"CVE-2019-14748","details":"An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implemented for file content checks; also, the output is not handled properly, causing persistent XSS that leads to cookie stealing or malicious actions. For example, a non-agent user can upload a .html file, and Content-Disposition will be set to inline instead of attachment.","modified":"2026-08-07T15:00:17.510863Z","published":"2019-08-07T17:15:12.417Z","references":[{"type":"ADVISORY","url":"https://github.com/osTicket/osTicket/releases/tag/v1.10.7"},{"type":"ADVISORY","url":"https://github.com/osTicket/osTicket/releases/tag/v1.12.1"},{"type":"FIX","url":"https://github.com/osTicket/osTicket/commit/33ed106b1602f559a660a69f931a9d873685d1ba"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/154003/osTicket-1.12-File-Upload-Cross-Site-Scripting.html"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/47224"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/osticket/osticket","events":[{"introduced":"0"},{"fixed":"dca01e13d14c423e0dc31f59c56c8d7fdf99a9da"},{"introduced":"a076918121f9490897dfe7d8a0ce58f2948df8bd"},{"fixed":"a8c4f57b19278cf11064f007b7a323f89fae45ff"},{"fixed":"33ed106b1602f559a660a69f931a9d873685d1ba"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.10.7"},{"introduced":"1.12"},{"fixed":"1.12.1"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:*"}}],"versions":["v1.12","v1.10.5","v1.10.3","v1.10.2","v1.10.1","v1.10","v1.9.5.1","v1.10-rc.3","v1.9.12","v1.9.11","v1.9.9","v1.9.8.1","v1.9.8","v1.9.7","v1.9.6","v1.9.5","v1.9.4","v1.9.4-rc5","v1.9.3","v1.9.2","v1.9.1","v1.9.0","v1.9-rc","v1.8.2-dpr","v1.8.1.2","v1.8.0.3","v1.8.0.1","v1.8.0.2","v1.8.0","v1.8.0-rc2","v1.8.0-rc1","v1.8-dpr"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14748.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}