SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Osticket_sts | Osticket | 1.2 (including) | 1.2 (including) |
| Osticket_sts | Osticket | 1.2.7 (including) | 1.2.7 (including) |
| Osticket_sts | Osticket | 1.3_beta (including) | 1.3_beta (including) |