CVE-2021-45811: SQL Injection
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topicid" URL parameters combination.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-45811.
What is the title of the vulnerability?
The title of the vulnerability is 'A SQL injection vulnerability in the Search functionality of tickets.php page in osTicket 1.15.x all...'
What is the severity of CVE-2021-45811?
The severity of CVE-2021-45811 is medium (6.5).
How does CVE-2021-45811 affect osTicket?
CVE-2021-45811 affects osTicket version 1.15.x.
How can an attacker exploit CVE-2021-45811?
An attacker can exploit CVE-2021-45811 by executing arbitrary SQL commands via the 'keywords' and 'topic_id' URL parameters combination in the 'Search' functionality of the 'tickets.php' page.
Are there any references for CVE-2021-45811?
Yes, the references for CVE-2021-45811 are: http://enhancesoft.com, http://osticket.com, and https://members.backbox.org/osticket-sql-injection/