CVE-2018-18527: Owndms Ownticket
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
OwnTicket 2018-05-23 allows SQL Injection via the showTicketId or editTicketStatusId parameter.
Affected products
- Owndms Ownticket: version 1.0 only
Published 2018-10-19. Last modified 2026-06-17.