CVE-2020-16193

Publication date

2020-08-26 12:00:17

Family

mitre

State

PUBLISHED

Description

osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info[notes] call.