← Vulnerability feed

Vulnerability record · CVE-2010-0606 · published 11 February 2010

CVE-2010-0606: Enhancesoft osticket cross-site scripting vulnerability

Enhancesoft · Osticket

Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/admin.php.

3.5 CVSS 2.0 Low EPSS 0.88% · top 42.6% CWE-79 · Cross-site scripting
3.5CVSS 2.0 base score
0.88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References, 2 tagged exploit
10 Jul 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/admin.php.

AV:N/AC:M/Au:S/C:N/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-0606 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42235Enhancesoft osticket sql injection vulnerabilitySQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile fu…EPSS 1.0%9.8CVE-2020-24881osTicket SSRF allows file upload and port scanningosTicket before 1.14.3 contains a server-side request forgery flaw. An attacker can use it to add a malicious file to the server or perform port scan…EPSS 73%analysed9.8CVE-2017-15580Osticket unrestricted file upload vulnerabilityosTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's c…EPSS 16%9.8CVE-2017-14396Osticket sql injection vulnerabilityIn osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstra…EPSS 2.9%8.8CVE-2022-31888Enhancesoft osticket vulnerabilitySession Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.EPSS 1.2%8.8CVE-2019-14749Enhancesoft osticket csv injection vulnerabilityAn issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionali…EPSS 9.6%8.7CVE-2026-22200osTicket PDF export PHP filter injection allows arbitrary file readosTicket versions 1.18.x before 1.18.3 and 1.17.x before 1.17.7 fail to sanitize rich-text HTML in tickets before it is processed by the mPDF generat…EPSS 74%analysed8.1CVE-2018-7195Enhancesoft osticket vulnerabilityEnhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging gu…EPSS 1.00%

Source: NIST National Vulnerability Database (record CVE-2010-0606), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.