osTicket Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-12629
include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.
include/class.sla.php in osTicket before 1.14.2 allows XSS via the SLA Name.