Osticket

Osticket

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 03.08.2026 00:00:00
  • Zuletzt bearbeitet 03.08.2026 20:17:22

osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an una...

  • EPSS 0.25%
  • Veröffentlicht 03.08.2026 00:00:00
  • Zuletzt bearbeitet 03.08.2026 20:17:22

A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title is stored without adequate HTML escaping and later rendered in multiple staff...

  • EPSS 0.46%
  • Veröffentlicht 03.08.2026 00:00:00
  • Zuletzt bearbeitet 03.08.2026 20:17:23

osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate...

  • EPSS 0.31%
  • Veröffentlicht 17.07.2026 14:55:32
  • Zuletzt bearbeitet 17.07.2026 18:10:00

osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.

  • EPSS 0.33%
  • Veröffentlicht 14.07.2026 00:00:00
  • Zuletzt bearbeitet 04.08.2026 18:16:50

osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip component and insufficient HTML sanitization, allowing remote attackers to execute arbitrary JavaScript in Agen...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 09.05.2026 19:30:09
  • Zuletzt bearbeitet 24.07.2026 08:10:00

A security vulnerability has been detected in osTicket up to 1.18.3. Impacted is an unknown function of the file include/class.dispatcher.php of the component Dispatcher. The manipulation of the argument _method leads to cross-site request forgery. R...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 02.04.2026 00:00:00
  • Zuletzt bearbeitet 24.07.2026 21:10:00

User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform.

  • EPSS 0.22%
  • Veröffentlicht 02.06.2025 00:00:00
  • Zuletzt bearbeitet 05.06.2025 14:11:24

osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 05.05.2025 00:00:00
  • Zuletzt bearbeitet 10.07.2026 18:20:35

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

Exploit
  • EPSS 15.56%
  • Veröffentlicht 23.10.2017 08:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a...