Record summary

CVE-2021-45811 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 26, 2024 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMosTicket 1.15.x - SQL InjectionCVSS 6.5

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

Impact

Authenticated attackers can exploit SQL injection in the Search functionality to extract sensitive database contents including user credentials and ticket information.

Remediation

Upgrade osTicket to later version to mitigate this vulnerability.

WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve2021osticketsqliauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:osticket:osticket:*:*:*:*:*:*:*:*
Shodan: title:"osTicket"
FOFA: title="osticket"
Google: intitle:"osticket"

Source: ProjectDiscovery

References

4