CVE-2020-16193: Enhancesoft Osticket

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.

Affected products

Published 2020-08-26. Last modified 2026-07-10.