PT-2026-2291 · Mpdf+1 · Mpdf+1
Naveen Sunkavally
·
Published
2026-01-12
·
Updated
2026-05-01
·
CVE-2026-22200
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
osTicket versions 1.17.x prior to 1.17.7 and 1.18.x prior to 1.18.3
Description
osTicket versions 1.17.x prior to 1.17.7 and 1.18.x prior to 1.18.3 contain an arbitrary file read issue in the ticket PDF export functionality. An attacker can submit a ticket with crafted rich-text HTML containing PHP filter expressions that are not properly sanitized before being processed by the mPDF PDF generator during export. Exporting the ticket to PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, potentially disclosing sensitive local files within the context of the osTicket application user. This is exploitable in default configurations where guests can create tickets and access ticket status, or where self-registration is enabled. The issue allows for the reading of arbitrary server files, including sensitive configuration data such as database credentials and secret key material.
Recommendations
Update to osTicket version 1.17.7 or later. Update to osTicket version 1.18.3 or later.
Exploit
Fix
RCE
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mpdf
Osticket