PT-2024-19022 · Joomla+2 · Joomla!+2

·

CVE-2024-21728

·

Published

2024-02-15

·

Updated

2024-12-03

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions osTicky2 versions prior to 2.2.8
Description An Open Redirect issue was discovered, allowing attackers to manipulate the return parameter in the URL to redirect to a malicious base64 encoded URL. This affects osTicky, a Joomla 3.x extension that integrates with osTicket, a popular support ticket system.
Recommendations For versions prior to 2.2.8, update to version 2.2.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the extension until a patch is applied.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-21728

Affected Products

Joomla!
Osticket
Osticky2