CVE-2017-15580
An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.6%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 15.56% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- osticket/osticket
- Source
- cve@mitre.org
References
- http://0day.today/exploits/28864Third Party Advisory
- http://nakedsecurity.com/cve/CVE-2017-15580/Third Party Advisory
- https://becomepentester.blogspot.com/2017/10/osTicket-File-Upload-Restrictions-Bypassed-CVE-2017-15580.htmlExploit, Third Party Advisory
- https://cxsecurity.com/issue/WLB-2017100187Exploit, Third Party Advisory
- https://packetstormsecurity.com/files/144747/osticket1101-shell.txtExploit, Third Party Advisory, VDB Entry
- https://www.cyber-security.ro/blog/2017/10/25/osticket-1-10-1-shell-upload/Broken Link
- https://www.exploit-db.com/exploits/45169/Exploit, Third Party Advisory, VDB Entry
- http://0day.today/exploits/28864Third Party Advisory
- http://nakedsecurity.com/cve/CVE-2017-15580/Third Party Advisory
- https://becomepentester.blogspot.com/2017/10/osTicket-File-Upload-Restrictions-Bypassed-CVE-2017-15580.htmlExploit, Third Party Advisory
- https://cxsecurity.com/issue/WLB-2017100187Exploit, Third Party Advisory
- https://packetstormsecurity.com/files/144747/osticket1101-shell.txtExploit, Third Party Advisory, VDB Entry
- https://www.cyber-security.ro/blog/2017/10/25/osticket-1-10-1-shell-upload/Broken Link
- https://www.exploit-db.com/exploits/45169/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.