Looking for the vulnerability index of Invicti's legacy products?
osTicket Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2025-26241 - Vulnerability Database

osTicket Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2025-26241

Medium
Reference: CVE-2025-26241
Title: osTicket Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

A SQL injection vulnerability in the quotSearchquot functionality of quottickets.phpquot page in osTicket lt1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the quotkeywordsquot and quottopic_idquot URL parameters combination.