Description
Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in db_loader.php where the multiple POST parameters (ticketsdb, ticketshost, ticketsuser, ticketspassword) are concatenated into mysqli connection arguments and dynamic SQL operating against an attacker-controlled database without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 3.44.2
References
github.com/openises/tickets/releases/tag/v3.44.2
github.com/...ommit/ecfeb406a016766cae81c749e14b5145a9f2dbff
www.vulncheck.com/...n-via-db-loader-php-multiple-parameters