CVE-2017-14396
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://www.osticket.com/blog/125
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| osticket | osticket | 1.10 | |
References
CWEs
CWE-89
Verify integrity in audit chain (admin only). AS-IS.