CVE-2004-0614: Medium severity osTicket Osticket Sts vulnerability
osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload a file of any size.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0614?
The severity of CVE-2004-0614 is considered medium due to the potential for remote attackers to exploit the vulnerability.
How do I fix CVE-2004-0614?
To fix CVE-2004-0614, ensure that file upload size limitations are implemented server-side rather than relying on client-side form fields.
What impact does CVE-2004-0614 have on osTicket?
CVE-2004-0614 allows remote attackers to bypass file upload size restrictions, which could lead to denial of service or resource exhaustion.
Which versions of osTicket are affected by CVE-2004-0614?
CVE-2004-0614 affects all versions of osTicket that trust hidden form fields for upload size limitations.
Is it safe to use osTicket if CVE-2004-0614 is present?
Using osTicket without addressing CVE-2004-0614 is risky, as it exposes the system to file upload vulnerabilities.