CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It involves a SQL injection risk.
CVE
CVE-2017-14396
Severity
CRITICAL
CVSS
9.8
EPSS
2.92%
Original NVD Description
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.
Related CVEs
Other vulnerabilities affecting the same vendor(s)