Description
Enhancesoft osTicket before 1.10.2 allows remote attackers to reset arbitrary passwords (when an associated e-mail address is known) by leveraging guest access and guessing a 6-digit number.
Remediation
References
Related Vulnerabilities
Apache HTTP Server Other Vulnerability (CVE-2002-1156)
Jenkins Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2024-43044)
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-4613)
MediaWiki Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2020-25827)