Vulnerabilities > Enhancesoft > Osticket > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-05-04 CVE-2021-42235 SQL Injection vulnerability in Enhancesoft Osticket
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.
network
low complexity
enhancesoft CWE-89
critical
9.8