Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
CVSS Metrics