H3-2025-0065¶
osTicket Anonymous Ticket Creation with Rich Text Content Enabled
| Category | SECURITY_MISCONFIGURATION |
| Base Score | 4.0 |
Description¶
The osTicket server is running with a default configuration that permits anyone to submit tickets containing rich-text content.
Impact¶
Anonymous users can submit tickets containing rich-text content, providing the opportunity to exploit potential vulnerabilities such as XSS, SSRF, or LFI.