CVE-2017-14396
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.
- Affected products
- Osticket
- Osticket
- = 1.10
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 2.9% (86th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2017-09-12
CVE-2017-14396 at NVD
1 known exploit for CVE-2017-14396
Proof-of-concept code and exploit modules indexed by Sploitus