CVE-2022-31890
SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function.
- Affected products
- Osticket
- Enhancesoft Audit Log
- < 2022-04-21
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.5% (73th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2023-04-05
CVE-2022-31890 at NVD
1 known exploit for CVE-2022-31890
Proof-of-concept code and exploit modules indexed by Sploitus