Total vulnerabilities in the database
osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload a file of any size.
CVSS v2:
No CWE or OWASP classifications available.