osTicket Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2021-42235 - Vulnerability Database
osTicket Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2021-42235
Critical
Reference:
CVE-2021-42235
Title:
osTicket Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.