Skip to content
Snippets Groups Projects
  • Peter Rotich's avatar
    Auth: Authentication Token Bypass · a9834d88
    Peter Rotich authored
    This commit addresses a vulnerability on how osTicket authenticates
    auth-tokens used for auto-login to view ticket status.
    
    The validation process failed to handle unexpected type handling issue
    making it possible for users to exploit type juggling and authenticate using
    only email and ticket number.
    a9834d88