CVE-2014-4744: Enhancesoft Osticket

Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in osTicket before 1.9.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Phone Number field to open.php or (2) Phone number field, (3) passwd1 field, (4) passwd2 field, or (5) do parameter to account.php.

Affected products

  • Enhancesoft Osticket: up to and including 1.9.1; version 1.0 only; version 1.2.7 only; version 1.3.0 only; version 1.6 only; version 1.6.0 only; …

Published 2014-07-09. Last modified 2026-07-10.