← Vulnerability feed

Vulnerability record · CVE-2022-31888 · published 5 April 2023

CVE-2022-31888: Enhancesoft osticket vulnerability

Enhancesoft · Osticket

Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.

8.8 CVSS 3.1 High EPSS 1.2% · top 32.7% CWE-384 · CWE-384
8.8CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-31888 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42235Enhancesoft osticket sql injection vulnerabilitySQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile fu…EPSS 1.0%9.8CVE-2020-24881osTicket SSRF allows file upload and port scanningosTicket before 1.14.3 contains a server-side request forgery flaw. An attacker can use it to add a malicious file to the server or perform port scan…EPSS 73%analysed8.8CVE-2019-14749Enhancesoft osticket csv injection vulnerabilityAn issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the export spreadsheets functionali…EPSS 9.6%8.7CVE-2026-22200osTicket PDF export PHP filter injection allows arbitrary file readosTicket versions 1.18.x before 1.18.3 and 1.17.x before 1.17.7 fail to sanitize rich-text HTML in tickets before it is processed by the mPDF generat…EPSS 74%analysed8.1CVE-2018-7195Enhancesoft osticket vulnerabilityEnhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging gu…EPSS 1.00%7.5CVE-2023-30082Enhancesoft osticket vulnerabilityA denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using th…EPSS 1.00%7.5CVE-2010-0605Enhancesoft osticket sql injection vulnerabilitySQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute a…EPSS 3.0%7.5CVE-2009-2361Enhancesoft osticket sql injection vulnerabilitySQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the s…EPSS 5.2%

Source: NIST National Vulnerability Database (record CVE-2022-31888), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.