Skip to main content
Loading…
    CVE-2017-15362 — osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link, aka XSS. Session ID and data theft may follow as well as the — CVE Database · The Intelligence Room