← Vulnerability feed

Vulnerability record · CVE-2020-24881 · published 2 November 2020

CVE-2020-24881: osTicket SSRF allows file upload and port scanning

Enhancesoft · Osticket

osTicket before 1.14.3 contains a server-side request forgery flaw. An attacker can use it to add a malicious file to the server or perform port scanning. The CVSS 3.1 base score is 9.8 (critical) with a network vector and no privileges or user interaction required.

9.8 CVSS 3.1 Critical EPSS 73% · top 0.5% CWE-918 · Server-side request forgery (SSRF)
9.8CVSS 3.1 base score, v2 7.5
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
10 Jul 2026Last modified by NVD

Description

SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction required, public exploit references, and very high EPSS probability make this a critical exposure.

What it is

osTicket before 1.14.3 contains a server-side request forgery flaw. An attacker can use it to add a malicious file to the server or perform port scanning. The CVSS 3.1 base score is 9.8 (critical) with a network vector and no privileges or user interaction required.

Impact

An attacker can make the server issue requests on their behalf, enabling internal port scanning and placement of a malicious file on the server. This can expose internal services and potentially lead to further compromise.

Attack surface

Reachable over the network via the vulnerable osTicket component; the CVSS vector AV:N/AC:L/PR:N/UI:N indicates no authentication and no user interaction are needed. The description does not name the exact endpoint or parameter.

Exploitation

Not listed in CISA KEV, but EPSS 30-day probability is 0.73449 (99.44th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. No ransomware group is documented using it.

What to do

  • Upgrade osTicket to 1.14.3 or later, applying the vendor patch commit d98c2d096aeb8876c6ab2f88317cd371d781f14d.
  • Restrict outbound network access from the osTicket host to only required destinations.
  • Place osTicket behind a reverse proxy or WAF that blocks requests to internal/private IP ranges.
  • Disable or restrict any osTicket feature that fetches remote URLs if not required.
  • Monitor the osTicket host for unexpected outbound connections and file writes.

Detection

  • Alert on outbound connections from the osTicket server to private or loopback IP ranges.
  • Review web server and application logs for requests containing internal IP addresses or unusual URL parameters.
  • Monitor for unexpected new files written to the osTicket web directory.
  • Correlate osTicket process activity with network scanning behavior toward internal hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-24881 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42235Enhancesoft osticket sql injection vulnerabilitySQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile fu…EPSS 1.0%8.8CVE-2022-31888Enhancesoft osticket vulnerabilitySession Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.EPSS 1.2%8.8CVE-2019-14749Enhancesoft osticket csv injection vulnerabilityAn issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionali…EPSS 9.6%8.7CVE-2026-22200osTicket PDF export PHP filter injection allows arbitrary file readosTicket versions 1.18.x before 1.18.3 and 1.17.x before 1.17.7 fail to sanitize rich-text HTML in tickets before it is processed by the mPDF generat…EPSS 74%analysed8.1CVE-2018-7195Enhancesoft osticket vulnerabilityEnhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging gu…EPSS 1.00%7.5CVE-2023-30082Enhancesoft osticket vulnerabilityA denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using th…EPSS 1.00%7.5CVE-2010-0605Enhancesoft osticket sql injection vulnerabilitySQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute a…EPSS 3.0%7.5CVE-2009-2361Enhancesoft osticket sql injection vulnerabilitySQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the s…EPSS 5.2%

Source: NIST National Vulnerability Database (record CVE-2020-24881), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.