GHSA-7x96-96qf-4vq9High
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading...
🔗 CVE IDs covered (1)
📋 Description
osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-14871
- https://fluidattacks.com/advisories/kyokai
- https://github.com/osTicket/osTicket
- https://github.com/osTicket/osTicket/releases/tag/v1.17.8
- https://github.com/osTicket/osTicket/releases/tag/v1.18.4
- https://medium.com/p/1abb8be847e6
- https://github.com/advisories/GHSA-7x96-96qf-4vq9