ZeroHour

CVE-2021-42235

CVSS 3.1
9.8 critical
EPSS
1%p61
Published
()
Modified
Description

SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.

Vendors
enhancesoft
Products
osticket
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.