Description
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
Remediation
References
Related Vulnerabilities
Oracle Application Server Other Vulnerability (CVE-2005-1495)
WordPress Plugin Google Authenticator-Per User Prompt Timing Attack (0.6)
WordPress Plugin WP Support Plus Responsive Ticket System Cross-Site Scripting (9.1.1)
WordPress 4.4.x Multiple Vulnerabilities (4.4 - 4.4.28)
WordPress Plugin Elementor Website Builder Cross-Site Scripting (2.8.4)