CVE-2020-24881

EUVD-2020-17589
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H