Description
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-2641 Vulnerability (CVE-2015-2641)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2609)
WordPress Plugin WORDPRESS VIDEO GALLERY SQL Injection (2.8)
Atlassian Jira URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-13402)
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-8419)