CVE-2020-24881
osTicket SSRF Vulnerability Allows File Upload and Port Scanning
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A Server-Side Request Forgery vulnerability exists in osTicket, allowing an unauthenticated attacker to upload malicious files to the server or scan network ports. This could potentially lead to unauthorized access or service disruption.