CVE-2018-7195: High severity osTicket osTicket vulnerability
Published Mar 27, 2018
·Updated
Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access and guessing a 6-digit number.
Affected Software
2 affected components
osTicket osTicket<=1.10.1
Enhancesoft osTicket<=1.10.1
Event History
Mar 27, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:29 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2018-7195?
CVE-2018-7195 is a vulnerability in Enhancesoft osTicket before version 1.10.2 that allows remote attackers to reset arbitrary passwords by guessing a 6-digit number.
2
How does CVE-2018-7195 work?
CVE-2018-7195 works by leveraging guest access and guessing a 6-digit number to reset arbitrary passwords when the associated email address is known.
3
What is the severity of CVE-2018-7195?
CVE-2018-7195 has a severity rating of 8.1 (high).
4
What is the affected software of CVE-2018-7195?
The affected software of CVE-2018-7195 is Enhancesoft osTicket before version 1.10.2.
5
How do I fix CVE-2018-7195?
To fix CVE-2018-7195, it is recommended to upgrade Enhancesoft osTicket to version 1.10.2 or later.