vendor:
osTicket
by:
r3j10r (Rajwinder Singh)
9.8
CVSS
CRITICAL
Arbitrary File Upload
22
CWE
Product Name: osTicket
Affected Version From: osTicket v1.10.1
Affected Version To: osTicket v1.10.1
Patch Exists: NO
Related CWE: CVE-2017-15580
CPE: a:osticket:osticket:1.10.1
Platforms Tested:
2018
osTicket 1.10.1 – Arbitrary File Upload
osTicket application provides a functionality to upload 'html' files with associated formats. However, application does not properly validate the content of file and accepts any type of files.
Mitigation:
The vendor should implement proper file validation and restrict file types to be uploaded.