Beveiligingsadvies

CVE-2017-14396

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2017-09-12 21:00:00
Laatst bijgewerkt 2024-08-05 19:27:40
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.