Tickets is prone to the following security vulnerabilities because it fails to sufficiently sanitize user-supplied input:1. A cross-site scripting vulnerability.2. An HTML-injection vulnerability.3. An information-disclosure vulnerability.
An attacker may leverage these issues to harvest sensitive information like user credentials, compromise the application, or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Tickets 2.20G is vulnerable; other versions may also be affected.
Vendor Status:
Currently we are not aware of any vendor-supplied patches