SQL Injection Vulnerability in osTicket 1.15.x
CVE-2021-45811
6.5MEDIUM
What is CVE-2021-45811?
A SQL injection vulnerability exists in the 'Search' function of the 'tickets.php' page in osTicket versions 1.15.x, enabling authenticated attackers to exploit vulnerable query parameters. By manipulating the 'keywords' and 'topic_id' parameters, attackers can execute arbitrary SQL commands, compromising the integrity and confidentiality of the database.
