CVE-2023-30082
Last modified
CVE-2023-30082 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop responding. EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using the osTicket application. This can cause the website to go down or stop responding. When a long password is entered, this procedure will consume all available CPU and memory.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Enhancesoft | Osticket | 1.17.2 |
References
- https://blog.manavparekh.com/2023/06/cve-2023-30082.htmlExploit, Third Party Advisory
- https://github.com/manavparekh/CVEs/blob/main/CVE-2023-30082/Steps%20to%20reproduce.txtExploit, Third Party Advisory
- https://blog.manavparekh.com/2023/06/cve-2023-30082.htmlExploit, Third Party Advisory
- https://github.com/manavparekh/CVEs/blob/main/CVE-2023-30082/Steps%20to%20reproduce.txtExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-30082?
How severe is CVE-2023-30082?
How do I fix CVE-2023-30082?
Are you affected by CVE-2023-30082?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
