Description
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
Remediation
References
Related Vulnerabilities
Magento Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-7851)
Ruby Improper Authentication Vulnerability (CVE-2007-5162)
Oracle Application Server CVE-2006-3714 Vulnerability (CVE-2006-3714)
WordPress Plugin WP-Backgrounds Lite Cross-Site Request Forgery (2.3)
Oracle HTTP Server Improper Encoding or Escaping of Output Vulnerability (CVE-2022-25235)