Impact
osTicket v1.18.3 and v1.17.7 contain a broken object‑level authorization flaw that enables an attacker to reference ticket objects directly. The vulnerability manifests as an insecure direct object reference within the AJAX ticket‑management subsystem and allows a user to view tickets that belong to other departments, effectively leaking confidential information. This is a direct breach of confidentiality, classified as CWE‑863.
Affected Systems
The affected product is osTicket from osTicket. The flaw exists in version 1.17.7 and 1.18.3. These releases run on Linux, macOS, and Windows platforms.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity. The EPSS score of less than 1 percent suggests a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, based on the description, it is inferred that the attack vector is a web‑based AJAX endpoint that can be accessed by authenticated users, an attacker with access to an account can request ticket identifiers from non‑department tickets and receive sensitive data. The vulnerability requires the attacker to be logged in but does not require elevated privileges, making it potentially exploitable in environments where role‑based department segregation is not strictly enforced.
OpenCVE Enrichment