CVE-2021-45811
osTicket 1.15.x - SQL Injection
Record summary
CVE-2021-45811 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 26, 2024 · Source: CVE List
Nuclei templates
1ProjectDiscoveryMEDIUMosTicket 1.15.x - SQL InjectionCVSS 6.5
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
Impact
Authenticated attackers can exploit SQL injection in the Search functionality to extract sensitive database contents including user credentials and ticket information.
Remediation
Upgrade osTicket to later version to mitigate this vulnerability.
Source: ProjectDiscovery