peter bassill · operator
$ cve CVE-2017-15580 JSON

CVE-2017-15580 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 15.6% (pctl 97)

Patch early

A public exploit exists.

Description

osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS15.56% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2017-10-23
Last modified2026-06-17

Affected (1)

VendorProduct
osticketosticket

Public exploits

SourceTitleDate
exploit-dbosTicket 1.10.1 - Arbitrary File Upload2018-08-08

References

→ the Explorer  ·  watch your stack  ·  NVD