SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.
| Software | From | Fixed in |
|---|---|---|
| osticket / osticket_sts | 1.2 | 1.2.x |
| osticket / osticket_sts | 1.3_beta | 1.3_beta.x |
| osticket / osticket_sts | 1.2.7 | 1.2.7.x |