Vulnerabilities > Enhancesoft > Audit LOG

DATE CVE VULNERABILITY TITLE RISK
2023-04-05 CVE-2022-31889 Cross-site Scripting vulnerability in Enhancesoft Audit LOG
Cross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae.
network
low complexity
enhancesoft CWE-79
6.1
2023-04-05 CVE-2022-31890 SQL Injection vulnerability in Enhancesoft Audit LOG
SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function.
network
low complexity
enhancesoft CWE-89
critical
9.8