CVE-2025-26241: SQL Injection
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topicid" URL parameters combination.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26241?
CVE-2025-26241 is considered a high severity vulnerability due to its potential for allowing authenticated attackers to execute arbitrary SQL commands.
How do I fix CVE-2025-26241?
To fix CVE-2025-26241, you should update your osTicket installation to a version higher than 1.17.5 where the vulnerability is patched.
Who is affected by CVE-2025-26241?
CVE-2025-26241 affects users of osTicket versions 1.17.5 and lower who utilize the 'Search' functionality on the tickets.php page.
Can CVE-2025-26241 be exploited remotely?
CVE-2025-26241 requires authenticated access to exploit, making it less likely to be exploited remotely by unauthenticated users.
What are the potential impacts of exploiting CVE-2025-26241?
Exploiting CVE-2025-26241 could allow attackers to manipulate the database, leading to data breaches, unauthorized data access, or data loss.