Description
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
Remediation
References
Related Vulnerabilities
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-18650)
MySQL CVE-2018-3200 Vulnerability (CVE-2018-3200)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6634)
WordPress Plugin Smart Flv 'jwplayer.swf' Multiple Cross-Site Scripting Vulnerabilities (1.0)
Atlassian Jira Exposure of Resource to Wrong Sphere Vulnerability (CVE-2021-39127)