S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 3, 2024

CVE-2020-24881 Scanner

CVE-2020-24881 Scanner - Server-Side Request Forgery (SSRF) vulnerability in osTicket

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-24881
9.8
CVSS

SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

osTicket is a widely used open-source ticket management system designed to help organizations handle customer support queries efficiently. It is employed by businesses of various sizes, primarily in IT helpdesks, customer support centers, and service organizations to streamline communication and improve issue tracking. With features like email ticketing, customizable forms, and multi-language support, osTicket is popular for enhancing support operations.

Server-Side Request Forgery (SSRF) is a critical vulnerability that allows attackers to force the server to make unintended HTTP requests to arbitrary destinations. Exploitation of this issue can lead to unauthorized access to internal services, sensitive data exposure, or further attacks against the infrastructure. SSRF can be exploited to execute port scanning or upload malicious files to the server.

In this specific case, osTicket versions below 1.14.3 are vulnerable to SSRF due to insufficient input validation on certain HTTP endpoints. Attackers can exploit this flaw by crafting malicious requests that manipulate how the server processes URLs or payloads. The issue arises from improperly sanitized input fields used for network-based communications.

Exploiting the SSRF vulnerability in osTicket can result in a range of consequences, including unauthorized access to internal systems, exposure of sensitive information, and potential lateral movement within a network. Attackers might also use this vulnerability to deliver malicious payloads or establish persistent backdoors in the affected server.

REFERENCES

Solution Advice
  • Upgrade to osTicket version 1.14.3 or later to mitigate this vulnerability.
  • Implement strict input validation and output sanitization to prevent malicious payloads.
  • Restrict network access to internal services and sensitive endpoints from the osTicket server.
  • Monitor and log server activity to identify and mitigate abnormal requests promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-24881 Scanner - Server-Side Request Forgery (SSRF) vulnerability in osTicket | S4E