CVE-2025-45387: XSS
Published Jun 2, 2025
·Updated
osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.
Affected Software
3 affected components
osTicket osTicket<1.17.6, <1.18.2
osTicket osTicket<1.17.6
osTicket osTicket>=1.18<1.18.2
Remediation
Event History
Jun 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-45387?
CVE-2025-45387 is classified as a high severity vulnerability due to its potential impact on user access control.
2
How do I fix CVE-2025-45387?
To fix CVE-2025-45387, upgrade your osTicket installation to version 1.17.6 or 1.18.2 or later.
3
What type of vulnerability is CVE-2025-45387?
CVE-2025-45387 is a Broken Access Control vulnerability found in the /scp/ajax.php file of osTicket.
4
What versions of osTicket are affected by CVE-2025-45387?
osTicket versions prior to 1.17.6 and 1.18.2 are affected by CVE-2025-45387.
5
What are the implications of CVE-2025-45387?
CVE-2025-45387 could allow unauthorized users to gain access to restricted resources or perform actions they shouldn't be able to.