CVE 8.7 HIGH

osTicket <= 1.18.2 PDF Export Arbitrary File Read_CVE-2026-22200

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Enhancesoft osTicket versions up to and including 1.18.2 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled.

AI Analysis

Arbitrary file read vulnerability in the ticket PDF export functionality

Basic Information

ID CVE-2026-22200
Source VulnCheck
Published Jan 12, 2026 at 18:34
Modified Jan 12, 2026 at 19:11

Affected Product

Vendor Enhancesoft
Product osTicket
Affected Versions Enhancesoft osTicket 0

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor Enhancesoft
Product osTicket
Version 1.18.2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.