{"id":"CVE-2020-24881","title":"SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.","summary":"SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-918"],"vendor":"enhancesoft","product":"osticket","affected":["osticket < 1.14.3"],"patched":["osticket 1.14.3"],"published":"2020-11-02","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-24881","references":[{"url":"http://packetstormsecurity.com/files/160995/osTicket-1.14.2-Server-Side-Request-Forgery.html","label":"cve@mitre.org"},{"url":"https://blackbatsec.medium.com/cve-2020-24881-server-side-request-forgery-in-osticket-eea175e147f0","label":"cve@mitre.org"},{"url":"https://github.com/osTicket/osTicket/commit/d98c2d096aeb8876c6ab2f88317cd371d781f14d","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/160995/osTicket-1.14.2-Server-Side-Request-Forgery.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://blackbatsec.medium.com/cve-2020-24881-server-side-request-forgery-in-osticket-eea175e147f0","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/osTicket/osTicket/commit/d98c2d096aeb8876c6ab2f88317cd371d781f14d","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.73449,"epssPercentile":0.99451,"exploitAvailable":true,"ingestedAt":"2026-07-10T19:05:51.252Z","exploits":{"exploitdb":true,"github":1,"githubRepos":["https://github.com/harshtech123/cve-2020-24881"],"nuclei":["CVE-2020-24881"],"checkedAt":"2026-09-25T08:20:37.538Z"},"slug":"CVE-2020-24881","body":"## Overview\n\nSSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.\n\n## Affected\n\n- `osticket < 1.14.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `osticket 1.14.3`","depth":"abyssal","depthScore":81,"depthScoreParts":{"impact":53.9,"likelihood":14.7,"exploitation":12,"ransomware":0},"changes":[]}