Password Reset Vulnerability in Enhancesoft osTicket
CVE-2018-7195

8.1HIGH

Key Information:

Vendor

Osticket

Status
Vendor
CVE Published:
27 March 2018

What is CVE-2018-7195?

A security flaw in Enhancesoft osTicket prior to version 1.10.2 permits remote attackers to reset user passwords if they know the associated email address. This vulnerability exploits guest access features and involves guessing a simple 6-digit numeric code, potentially compromising user accounts and sensitive information. It highlights the importance of implementing robust security measures to prevent unauthorized password resets.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.