Description
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
Remediation
References
Related Vulnerabilities
Oracle Application Server CVE-2007-3854 Vulnerability (CVE-2007-3854)
WordPress Plugin Custom Admin Page by BestWebSoft Cross-Site Scripting (0.1.1)
Drupal Core 7.x Cross-Site Scripting (7.0 - 7.79)
Internet Information Services Other Vulnerability (CVE-2002-1744)
TYPO3 Deserialization of Untrusted Data Vulnerability (CVE-2019-19849)