CVE-2026-14871 - osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure

CVE ID :CVE-2026-14871
Published : July 17, 2026, 2:55 p.m. | 1 hour, 23 minutes ago
Description :osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

from Latest Vulnerabilities https://ift.tt/XawIEiL

Post a Comment

Previous Post Next Post