A vulnerability was found in LINE osTicket 1.18.3 and classified as problematic. Affected is an unknown function of the file include/staff/templates/thread-entry.tmpl.php of the component Thread Entry Title. Executing a manipulation of the argument Title can lead to cross site scripting.
This vulnerability appears as CVE-2026-38446. The attack may be performed from remote. There is no available exploit.