CVE-2020-16193
About
osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.
Rainforest analyst review
osTicket fails to sanitize a notes field before echoing it, producing cross-site scripting. To land it an attacker needs a low-privilege authenticated account, and to fire the payload a victim has to view the affected page, so both an account and a target are required.
In a help-desk system the interesting victims are staff who read tickets, and XSS there could ride a support agent's session. But the authentication and interaction requirements keep this out of drive-by territory; it's a targeted or insider-flavored issue rather than something scanners exploit at scale.
We treat this as moderate and worth folding into routine patching. The useful data point is which osTicket instances are running and at what version, so the affected ones can be updated before someone chains the XSS into session theft against staff accounts.
References
Related CVEs
Frequently asked questions
What is CVE-2020-16193?
osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.
How severe is CVE-2020-16193?
CVE-2020-16193 carries a CVSS 3.1 base score of 5.4, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 59 out of 100, in the elevated band.
How is CVE-2020-16193 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N): attack vector Network, attack complexity Low, privileges required Low, user interaction Required. Impact on confidentiality Low, integrity Low and availability None.
Which products are affected by CVE-2020-16193?
Public advisories list the following as affected: osticket. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2020-16193?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
