9.8
CVSSv3

CVE-2017-14396

Published: 12/09/2017 Updated: 21/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In osTicket prior to 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.

Vulnerable Product Search on Vulmon Subscribe to Product

osticket osticket 1.10

Exploits

1 ADVISORY INFORMATION ======================================== Title: osTicket v110 Unauthenticated SQL Injection Application: osTicket Bugs: SQL Injection Class: Sensitive Information disclosure Remotely Exploitable: Yes Authentication Required: NO Versions Affected: <= v110 Technology: PHP Vendor URL: osticketcom/ CVSSv3 Score: 10 ...