CVE-2020-24881: Enhancesoft Osticket

Critical severity, CVSS 9.8. EPSS: 73.4% chance of exploitation in the next 30 days.

SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

Affected products

Published 2020-11-02. Last modified 2026-07-10.