osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an unauthenticated attacker sends a reply email to an existing ticket from an unregistered address with an XSS payload in the From display name.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Mon, 03 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Osticket
Osticket osticket |
|
| Vendors & Products |
Osticket
Osticket osticket |
Mon, 03 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an unauthenticated attacker sends a reply email to an existing ticket from an unregistered address with an XSS payload in the From display name. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-03T19:31:07.711Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38444
Updated: 2026-08-03T19:31:03.929Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-03T19:30:04Z