Vulnerability Description
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Enhancesoft | Osticket | < 1.14.8 |
Related Weaknesses (CWE)
References
- https://github.com/osTicket/osTicket/commit/e28291022e662ffa754e170c09cade7bdadfPatchThird Party Advisory
- https://github.com/osTicket/osTicket/commit/e28291022e662ffa754e170c09cade7bdadfPatchThird Party Advisory
FAQ
What is CVE-2021-42235?
CVE-2021-42235 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.
How severe is CVE-2021-42235?
CVE-2021-42235 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-42235?
Check the references section above for vendor advisories and patch information. Affected products include: Enhancesoft Osticket.