📦 Osticket

by Enhancesoft

🔍 What is Osticket?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-42235

CRITICAL CVSS 9.8 May 4, 2022

This SQL injection vulnerability in osTicket's login and password reset functionality allows attackers to execute arbitrary SQL commands. It affects all osTicket installations before versions 1.14.8 a...

CVE-2026-22200

HIGH CVSS 7.5 Jan 12, 2026

This vulnerability allows remote attackers to read arbitrary files from the osTicket server filesystem by crafting malicious HTML in ticket content and exporting it to PDF. Attackers can disclose sens...

CVE-2023-30082

HIGH CVSS 7.5 Jun 14, 2023

CVE-2023-30082 is a denial-of-service vulnerability in osTicket where submitting an extremely long password (over 10 million characters) causes excessive CPU and memory consumption, potentially crashi...

CVE-2022-31888

HIGH CVSS 8.8 Apr 5, 2023

This CVE describes a session fixation vulnerability in osTicket's authentication system. Attackers can fixate session IDs before user login, potentially hijacking authenticated sessions after login. A...