Vulnerability Description
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Osticket | Osticket | 1.10.1 |
Related Weaknesses (CWE)
References
- http://0day.today/exploits/28864Third Party Advisory
- http://nakedsecurity.com/cve/CVE-2017-15580/Third Party Advisory
- https://becomepentester.blogspot.com/2017/10/osTicket-File-Upload-Restrictions-BExploitThird Party Advisory
- https://cxsecurity.com/issue/WLB-2017100187ExploitThird Party Advisory
- https://packetstormsecurity.com/files/144747/osticket1101-shell.txtExploitThird Party AdvisoryVDB Entry
- https://www.cyber-security.ro/blog/2017/10/25/osticket-1-10-1-shell-upload/Broken Link
- https://www.exploit-db.com/exploits/45169/ExploitThird Party AdvisoryVDB Entry
- http://0day.today/exploits/28864Third Party Advisory
- http://nakedsecurity.com/cve/CVE-2017-15580/Third Party Advisory
- https://becomepentester.blogspot.com/2017/10/osTicket-File-Upload-Restrictions-BExploitThird Party Advisory
- https://cxsecurity.com/issue/WLB-2017100187ExploitThird Party Advisory
- https://packetstormsecurity.com/files/144747/osticket1101-shell.txtExploitThird Party AdvisoryVDB Entry
- https://www.cyber-security.ro/blog/2017/10/25/osticket-1-10-1-shell-upload/Broken Link
- https://www.exploit-db.com/exploits/45169/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-15580?
CVE-2017-15580 is a vulnerability with a CVSS score of 9.8 (CRITICAL). osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as ...
How severe is CVE-2017-15580?
CVE-2017-15580 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-15580?
Check the references section above for vendor advisories and patch information. Affected products include: Osticket Osticket.