PT-2023-13055 · Osticket · Osticket

Published

2023-04-05

·

Updated

2025-02-13

·

CVE-2022-31890

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions osTicket-plugins versions prior to commit a7842d494889fd5533d13deb3c6a7789768795ae
Description The issue is related to a SQL Injection vulnerability in the audit/class.audit.php file. It can be exploited via the order parameter to the getOrder function.
Recommendations For osTicket-plugins versions prior to commit a7842d494889fd5533d13deb3c6a7789768795ae, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the getOrder function or avoiding the use of the order parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-31890

Affected Products

Osticket