EXPOSURES › CVE-2020-24881
CVE-2020-24881
CRITICAL
DETAIL
SourceNVD · cve
Published2020-11-02
CVSS9.8
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-24881 ↗
SHAME 35/100
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
SENTIMENT · TRUSTED SOURCES
synthesis
severe-fallout
-0.50
Negative sentiment due to critical SSRF vulnerability in osTicket allowing file upload and port scanning, though sources are generic databases rather than direct vendor condemnation.
Critical vulnerability disclosed
"SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning."
Neutral NVD page
Neutral database listing
Neutral advisory database
Irrelevant topic
Irrelevant topic
Irrelevant topic
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.