CVE-2022-31888: High severity osticket vulnerability
Published Apr 5, 2023
·Updated
Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.
Affected Software
1 affected component
Enhancesoft osTicket<=1.16.2
Remediation
Event History
Apr 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-31888?
CVE-2022-31888 is classified as a high severity vulnerability due to its potential for session fixation attacks.
2
How do I fix CVE-2022-31888?
To fix CVE-2022-31888, upgrade to osTicket version 1.16.3 or later.
3
What type of vulnerability is CVE-2022-31888?
CVE-2022-31888 is a session fixation vulnerability that affects the login functionality in osTicket.
4
Which versions of osTicket are affected by CVE-2022-31888?
CVE-2022-31888 affects osTicket versions up to and including 1.16.2.
5
Where can I find more information about CVE-2022-31888?
More information about CVE-2022-31888 can typically be found in the release notes or security advisories provided by osTicket.