← Vulnerability feed

Vulnerability record · CVE-2019-14749 · published 7 August 2019

CVE-2019-14749: Enhancesoft osticket csv injection vulnerability

Enhancesoft · Osticket

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user input in the Name and Internal Notes fields in the Users tab, and the Issue Summary field in the tickets tab. This allows other agents to download data in a .csv file format or .xls file format. This is used as input for spreadsheet applications such as Excel and OpenOffice Calc, resulting in a situation where cells in the spreadsheets can contain input from an untrusted source. As a result, the end user who is accessing the exported spreadsheet can be affected.

8.8 CVSS 3.0 High EPSS 9.6% · top 4.7% CWE-1236 · CSV injection
8.8CVSS 3.0 base score, v2 6.8
9.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
10 Jul 2026Last modified by NVD

Description

An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionality. These spreadsheets are generated dynamically from unvalidated or unfiltered user input in the Name and Internal Notes fields in the Users tab, and the Issue Summary field in the tickets tab. This allows other agents to download data in a .csv file format or .xls file format. This is used as input for spreadsheet applications such as Excel and OpenOffice Calc, resulting in a situation where cells in the spreadsheets can contain input from an untrusted source. As a result, the end user who is accessing the exported spreadsheet can be affected.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-14749 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42235Enhancesoft osticket sql injection vulnerabilitySQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile fu…EPSS 1.0%9.8CVE-2020-24881osTicket SSRF allows file upload and port scanningosTicket before 1.14.3 contains a server-side request forgery flaw. An attacker can use it to add a malicious file to the server or perform port scan…EPSS 73%analysed8.8CVE-2022-31888Enhancesoft osticket vulnerabilitySession Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.EPSS 1.2%8.7CVE-2026-22200osTicket PDF export PHP filter injection allows arbitrary file readosTicket versions 1.18.x before 1.18.3 and 1.17.x before 1.17.7 fail to sanitize rich-text HTML in tickets before it is processed by the mPDF generat…EPSS 74%analysed8.1CVE-2018-7195Enhancesoft osticket vulnerabilityEnhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging gu…EPSS 1.00%7.5CVE-2023-30082Enhancesoft osticket vulnerabilityA denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using th…EPSS 1.00%7.5CVE-2010-0605Enhancesoft osticket sql injection vulnerabilitySQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute a…EPSS 3.0%7.5CVE-2009-2361Enhancesoft osticket sql injection vulnerabilitySQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the s…EPSS 5.2%

Source: NIST National Vulnerability Database (record CVE-2019-14749), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.