vendor:
osTicket
by:
Mehmet Ince
N/A
CVSS
N/A
SQL Injection
89
CWE
Product Name: osTicket
Affected Version From: <= v1.10
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: osticket
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Python
2017
osTicket v1.10 Unauthenticated SQL Injection
The vulnerability allows remote attackers to execute a sql query on database system.
Mitigation:
Upgrade to osTicket version 1.10 or later.