Home / Companies / Sonar / Blog / Post Details
Content Deep Dive

Pitfalls of Desanitization: Leaking Customer Data from osTicket

Blog post from Sonar

Post Details
Company
Date Published
Author
Oskar Zeino-Mahmalat
Word Count
1,991
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

Researchers have identified a dangerous coding pattern called Desanitization that can lead to numerous impactful XSS vulnerabilities in prominent software. This pattern involves potentially harmful user input being sanitized and then altered afterward, negating the sanitization process and making the input dangerous again. An example of this is a Cross-Site Scripting (XSS) vulnerability found in osTicket, an open-source helpdesk software used by companies to provide solutions to customers seeking help. The issue has been fixed in osTicket versions v1.18.1 and v1.17.5.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.