osTicket Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2021-45811 - Vulnerability Database

osTicket Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2021-45811

Medium
Reference: CVE-2021-45811
Title: osTicket Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

A SQL injection vulnerability in the quotSearchquot functionality of quottickets.phpquot page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the quotkeywordsquot and quottopic_idquot URL parameters combination.