osTicket Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2025-26241
A SQL injection vulnerability in the quotSearchquot functionality of quottickets.phpquot page in osTicket lt1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the quotkeywordsquot and quottopic_idquot URL parameters combination.