{"id":"CVE-2021-42235","details":"SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.","modified":"2026-08-07T16:57:44.615855Z","published":"2022-05-04T17:15:08.087Z","references":[{"type":"FIX","url":"https://github.com/osTicket/osTicket/commit/e28291022e662ffa754e170c09cade7bdadf3fd9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/osticket/osticket","events":[{"introduced":"0"},{"fixed":"7398e9006f3847d89359119be17fe18eb94eef53"},{"introduced":"d5ee0df82cde86f0ec7fd2726a156ab07929bd68"},{"fixed":"6bd7884f067e440bafbe7b181941f95a46d61792"},{"fixed":"e28291022e662ffa754e170c09cade7bdadf3fd9"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:enhancesoft:osticket:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.14.8"},{"introduced":"1.15"},{"fixed":"1.15.4"}]}}],"versions":["v1.15.3.1","v1.14.7","v1.12.2","v1.15.3","v1.15.2","v1.14.6","v1.15.1","v1.14.5","v1.14.4","v1.14.3","v1.14.2","v1.14.1","v1.14","v1.14-rc2","v1.14.-rc1","v1.12.1","v1.12","v1.11","v1.11.0-rc1","v1.10.1","v1.10","v1.9.5.1","v1.10-rc.3","v1.9.12","v1.9.11","v1.9.9","v1.9.8.1","v1.9.8","v1.9.7","v1.9.6","v1.9.5","v1.9.4","v1.9.4-rc5","v1.9.3","v1.9.2","v1.9.1","v1.9.0","v1.9-rc","v1.8.2-dpr","v1.8.1.2","v1.8.0.3","v1.8.0.1","v1.8.0.2","v1.8.0","v1.8.0-rc2","v1.8.0-rc1","v1.8-dpr"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-42235.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}