CVE-2020-16193: Enhancesoft Osticket
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.
Affected products
- Enhancesoft Osticket: before 1.14.3 (fixed in 1.14.3)
Published 2020-08-26. Last modified 2026-07-10.