Broken Access Control Vulnerability in osTicket by osTicket Team
CVE-2025-45387

5.4MEDIUM

Key Information:

Vendor

osTicket

Status
Vendor
CVE Published:
2 June 2025

What is CVE-2025-45387?

Earlier versions of osTicket, specifically prior to v1.17.6 and v1.18.2, are subject to a vulnerability that allows unauthorized access through the /scp/ajax.php file. This flaw can enable attackers to exploit broken access controls, leading to potential manipulation of sensitive data and unauthorized actions within the application, thereby jeopardizing the security and integrity of the system.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.