osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Osticket_sts | Osticket | 1.2 (including) | 1.2 (including) |