CVE-2022-31890: SQL Injection
Published Apr 5, 2023
·Updated
SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function.
Affected Software
1 affected component
Enhancesoft Audit Log Osticket<2022-04-21
Remediation
Event History
Apr 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this SQL Injection vulnerability?
The vulnerability ID for this SQL Injection vulnerability is CVE-2022-31890.
2
What is the title of this vulnerability?
The title of this vulnerability is 'SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a784…'
3
Where is the SQL Injection vulnerability located?
The SQL Injection vulnerability is located in audit/class.audit.php in osTicket osTicket-plugins.
4
What is the severity rating for this vulnerability?
The severity rating for this vulnerability is critical.
5
How can I fix this SQL Injection vulnerability?
To fix this SQL Injection vulnerability, you need to update osTicket osTicket-plugins to commit a7842d494889fd5533d13deb3c6a7789768795ae or later.