---
id: CVE-2020-24881
title: >-
  SSRF exists in osTicket before 1.14.3, where an attacker can add malicious
  file to server or perform port scanning.
summary: >-
  SSRF exists in osTicket before 1.14.3, where an attacker can add malicious
  file to server or perform port scanning.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-918
vendor: enhancesoft
product: osticket
affected:
  - osticket < 1.14.3
patched:
  - osticket 1.14.3
published: '2020-11-02'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-24881'
references:
  - url: >-
      http://packetstormsecurity.com/files/160995/osTicket-1.14.2-Server-Side-Request-Forgery.html
    label: cve@mitre.org
  - url: >-
      https://blackbatsec.medium.com/cve-2020-24881-server-side-request-forgery-in-osticket-eea175e147f0
    label: cve@mitre.org
  - url: >-
      https://github.com/osTicket/osTicket/commit/d98c2d096aeb8876c6ab2f88317cd371d781f14d
    label: cve@mitre.org
  - url: >-
      http://packetstormsecurity.com/files/160995/osTicket-1.14.2-Server-Side-Request-Forgery.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://blackbatsec.medium.com/cve-2020-24881-server-side-request-forgery-in-osticket-eea175e147f0
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/osTicket/osTicket/commit/d98c2d096aeb8876c6ab2f88317cd371d781f14d
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.73449
epssPercentile: 0.99451
exploitAvailable: true
ingestedAt: '2026-07-10T19:05:51.252Z'
exploits:
  exploitdb: true
  github: 1
  githubRepos:
    - 'https://github.com/harshtech123/cve-2020-24881'
  nuclei:
    - CVE-2020-24881
  checkedAt: '2026-09-25T08:20:37.538Z'
---

## Overview

SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.

## Affected

- `osticket < 1.14.3`

## Remediation

Upgrade past the affected range:

- `osticket 1.14.3`
