Description
A security vulnerability has been detected in osTicket up to 1.18.3. Impacted is an unknown function of the file include/class.dispatcher.php of the component Dispatcher. The manipulation of the argument _method leads to cross-site request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a pull request but has not reacted yet.
Problem types
Timeline
| 2026-05-08: | Advisory disclosed |
| 2026-05-08: | VulDB entry created |
| 2026-05-08: | VulDB entry last update |
Credits
AliAz (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/362346 (VDB-362346 | osTicket Dispatcher class.dispatcher.php cross-site request forgery)
vuldb.com/vuln/362346/cti (VDB-362346 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/802755 (Submit #802755 | osTicket 1.18.3 Cross-Site Request Forgery)
github.com/osTicket/osTicket/pull/6945
github.com/...y-advisories/blob/main/csrf_bypass_osTicket.md
github.com/osTicket/osTicket/