CRITICAL
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php
Published Sep 12, 2017
9.8
CRITICALCVSS 3.0
EPSS 2.92%
Description
Affected products
Remediation
References (1)
Change history (0)
No recorded changes yet.