Skip to content
Snippets Groups Projects
Commit a9834d88 authored by Peter Rotich's avatar Peter Rotich
Browse files

Auth: Authentication Token Bypass

This commit addresses a vulnerability on how osTicket authenticates
auth-tokens used for auto-login to view ticket status.

The validation process failed to handle unexpected type handling issue
making it possible for users to exploit type juggling and authenticate using
only email and ticket number.
parent 6e039ab7
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment