Page 2 of 11 results (0.001 seconds)
CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0
CVE-2021-42235
https://notcve.org/view.php?id=CVE-2021-42235
04 May 2022 — SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality. Una inyección SQL en el proceso de inicio de sesión y restablecimiento de contraseña de osTicket versiones anteriores a 1.14.8 y 1.15.4, permite a atacantes acceder a la funcionalidad osTicket administration profile • https://github.com/osTicket/osTicket/commit/e28291022e662ffa754e170c09cade7bdadf3fd9 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •