CVE-2025-45387: Osticket

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.

Affected products

  • Osticket Osticket: before 1.17.6 (fixed in 1.17.6); from 1.18, before 1.18.2 (fixed in 1.18.2)

Published 2025-06-02. Last modified 2026-06-17.