CVE-2017-14396 | osTicket 1.10 file.php key sql injection (EDB-42660 / ID 800981)
A vulnerability was found in osTicket 1.10 and classified as critical. Affected is an unknown function of the file file.php. The manipulation of the argument key as part of Parameter results in sql injection.
This vulnerability is identified as CVE-2017-14396. The attack can be executed remotely. Additionally, an exploit exists.