SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.
| Software | From | Fixed in |
|---|---|---|
| enhancesoft / osticket | 1.15 | 1.15.4 |
| enhancesoft / osticket | - | 1.14.8 |