Skip to content

H3-2025-0064

osTicket Self-Signup Enabled

Category SECURITY_MISCONFIGURATION
Base Score 4.0

Description

The osTicket server is running with a default configuration that permits anyone to create accounts.

Impact

Unauthenticated users can create accounts and open tickets, providing the opportunity to exploit potential vulnerabilities such as XSS, SSRF, or LFI.

References