CVE-2021-45811
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 2.5%
exploitation probability
2.5%top 17% of all CVEs
observed exploitation
nono source reports it
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
Affected products
n/a · n/a