Skip to content
COOEY

EXPOSURES › CVE-2020-24881

CVE-2020-24881

CRITICAL
DETAIL
SourceNVD · cve Published2020-11-02 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-24881 ↗
SHAME 35/100

SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.50
Negative sentiment due to critical SSRF vulnerability in osTicket allowing file upload and port scanning, though sources are generic databases rather than direct vendor condemnation.
cooey ↗ severe-fallout -0.80
Critical vulnerability disclosed
"SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning."
NVD ↗ severe-fallout +0.00
Neutral NVD page
www.cvefind.com ↗ severe-fallout +0.00
Neutral database listing
advisories.gitlab.com ↗ severe-fallout +0.00
Neutral advisory database
www.databreachtoday.com ↗ severe-fallout +0.00
Irrelevant topic
CISA ↗ severe-fallout +0.00
Irrelevant topic
www.vulncheck.com ↗ severe-fallout +0.00
Irrelevant topic
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.