Skip to content

H3-2025-0065

osTicket Anonymous Ticket Creation with Rich Text Content Enabled

Category SECURITY_MISCONFIGURATION
Base Score 4.0

Description

The osTicket server is running with a default configuration that permits anyone to submit tickets containing rich-text content.

Impact

Anonymous users can submit tickets containing rich-text content, providing the opportunity to exploit potential vulnerabilities such as XSS, SSRF, or LFI.

References