Back

CVE-2005-2153

SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.

Published: Jul 6, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
osticket osticket_sts 1.2
osticket osticket_sts 1.2.7
osticket osticket_sts 1.3_beta

GitHub Security Advisory GHSA-63vq-qp86-c7m4

SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.33%

Top 31% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub