Broken Access Control Vulnerability in osTicket by osTicket Team
CVE-2025-45387
5.4MEDIUM
What is CVE-2025-45387?
Earlier versions of osTicket, specifically prior to v1.17.6 and v1.18.2, are subject to a vulnerability that allows unauthorized access through the /scp/ajax.php file. This flaw can enable attackers to exploit broken access controls, leading to potential manipulation of sensitive data and unauthorized actions within the application, thereby jeopardizing the security and integrity of the system.
