Vulnerabilities > Enhancesoft > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-04-05 CVE-2022-31890 SQL Injection vulnerability in Enhancesoft Audit LOG
SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function.
network
low complexity
enhancesoft CWE-89
critical
9.8
2022-05-04 CVE-2021-42235 SQL Injection vulnerability in Enhancesoft Osticket
SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.
network
low complexity
enhancesoft CWE-89
critical
9.8