CVE-2022-31890 is a critical SQL Injection vulnerability found in the audit/class.audit.php component of osTicket-plugins, specifically affecting the enhancesoft audit_log plugin, prior to commit a7842d494889fd5533d13deb3c6a7789768795ae. This flaw, exploitable via the 'order' parameter in the getOrder function, carries a CVSS score of 9.8 (Critical), indicating a network-exploitable vulnerability with low attack complexity that can lead to complete compromise of confidentiality, integrity, and availability. Despite its high severity and potential for significant impact, there is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2022-04-21CPE matchmatch criteria | cpe:2.3:a:enhancesoft:audit_log:*:*:*:*:*:osticket:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.