osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.
https://exchange.xforce.ibmcloud.com/vulnerabilities/16478
https://exchange.xforce.ibmcloud.com/vulnerabilities/16477
https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-0612