H3-2025-0064¶
osTicket Self-Signup Enabled
| Category | SECURITY_MISCONFIGURATION |
| Base Score | 4.0 |
Description¶
The osTicket server is running with a default configuration that permits anyone to create accounts.
Impact¶
Unauthenticated users can create accounts and open tickets, providing the opportunity to exploit potential vulnerabilities such as XSS, SSRF, or LFI.