Vulnerabilities > Osticket > Osticket > 1.12.2

DATE CVE VULNERABILITY TITLE RISK
2020-11-02 CVE-2020-24881 Server-Side Request Forgery (SSRF) vulnerability in Osticket
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
network
low complexity
osticket CWE-918
7.5
2020-08-30 CVE-2020-24917 Cross-site Scripting vulnerability in Osticket
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.
network
osticket CWE-79
4.3
2020-08-26 CVE-2020-16193 Cross-site Scripting vulnerability in Osticket
osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.
network
osticket CWE-79
3.5