CVE-2021-42235: SQL Injection
Published May 4, 2022
·Updated
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.
Affected Software
2 affected components
Enhancesoft osTicket<1.14.8
Enhancesoft osTicket>=1.15<1.15.4
Remediation
Event History
May 4, 2022
CVE Published
via MITRE·04:56 PM
Data Sourced
via MITRE·04:56 PM
Description
Frequently Asked Questions
1
What is CVE-2021-42235?
CVE-2021-42235 refers to a SQL injection vulnerability in the login and password reset process of osTicket versions before 1.14.8 and 1.15.4.
2
What is the severity of CVE-2021-42235?
CVE-2021-42235 has a severity rating of 9.8 (critical).
3
How does CVE-2021-42235 impact osTicket?
CVE-2021-42235 allows attackers to access the osTicket administration profile functionality by exploiting a SQL injection vulnerability in the login and password reset process.
4
Which versions of osTicket are affected by CVE-2021-42235?
osTicket versions before 1.14.8 and 1.15.4 are affected by CVE-2021-42235.
5
How can I fix CVE-2021-42235?
To fix CVE-2021-42235, it is recommended to upgrade osTicket to version 1.14.8 or 1.15.4.