PT-2024-19022 · Joomla+2 · Joomla!+2

Matei Josephs

·

Published

2024-02-15

·

Updated

2024-12-03

·

CVE-2024-21728

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions osTicky2 versions prior to 2.2.8
Description An Open Redirect issue was discovered, allowing attackers to manipulate the return parameter in the URL to redirect to a malicious base64 encoded URL. This affects osTicky, a Joomla 3.x extension that integrates with osTicket, a popular support ticket system.
Recommendations For versions prior to 2.2.8, update to version 2.2.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the extension until a patch is applied.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2024-21728

Affected Products

Joomla!
Osticket
Osticky2