Executive brief
osTicket is a help-desk ticketing system used to manage customer support requests. A flaw in how osTicket processes reply emails allows an unauthenticated attacker to inject malicious JavaScript code via the sender's display name, which is then stored and executed in the browsers of staff and customers viewing the affected ticket. This can lead to session hijacking, unauthorized ticket actions, and exposure of sensitive customer data.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in osTicket's email processing pipeline. When osTicket receives an inbound reply to an existing ticket (via Thread::postEmail() in include/class.mailparse.php), the sender's display name from the RFC 2822 From header is extracted without HTML sanitization and stored directly in the poster column of the ost_thread_entry database table. The vulnerability manifests only when the sender's email address is unregistered in the system, causing the template layer to output the raw poster value without encoding in staff views, client portal views, preview panes, and ticket export pages. An unauthenticated attacker can exploit this by sending a crafted reply email with a valid In-Reply-To header and an XSS payload embedded in the From display name (e.g., "<img src=x onerror=alert(document.cookie)>"). The payload executes persistently in any staff member's or end user's browser upon ticket access. The root cause is missing input sanitization in ThreadEntry::add() and output encoding in multiple template files; a similar title field in the same function receives Format::sanitize(), but the poster field was omitted. As of publication, no patch has been released.
Affected products
- Enhancesoft LLC osTicket 1.18.3 and earlier
Timeline
- 2026-08-03: disclosed: CVE-2026-38444 published