CVE-2017-15580
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.
- Affected products
- Osticket
- Osticket
- = 1.10.1
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 15.6% (97th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2017-10-23
CVE-2017-15580 at NVD
4 known exploits for CVE-2017-15580
Proof-of-concept code and exploit modules indexed by Sploitus