CVE-2017-14396: SQL Injection
Published Sep 12, 2017
·Updated
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.
Affected Software
1 affected component
osTicket osTicket=1.10
Remediation
Patch Available
Event History
Sep 12, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14396?
CVE-2017-14396 has a moderate severity level due to the potential for SQL injection.
2
How do I fix CVE-2017-14396?
To fix CVE-2017-14396, upgrade osTicket to version 1.10.1 or later.
3
What type of vulnerability is CVE-2017-14396?
CVE-2017-14396 is an SQL injection vulnerability.
4
Which versions of osTicket are affected by CVE-2017-14396?
CVE-2017-14396 affects osTicket versions prior to 1.10.1.
5
What can an attacker do with CVE-2017-14396?
An attacker can exploit CVE-2017-14396 to execute arbitrary SQL queries against the database.