CWE-38: Path Traversal: '\absolute\pathname\here'
The product accepts input in the form of a backslash absolute path ('\absolute\pathname\here') without appropriate validation, which can allow an attacker to traverse the file system to unintended locations or access arbitrary files.
1 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-9507 — Session fixation vulnerability in Enhancesoft's osTicket
Recently published
- CVE-2026-9507 — Session fixation vulnerability in Enhancesoft's osTicket