CVE-2018-18527: Owndms Ownticket

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

OwnTicket 2018-05-23 allows SQL Injection via the showTicketId or editTicketStatusId parameter.

Affected products

  • Owndms Ownticket: version 1.0 only

Published 2018-10-19. Last modified 2026-06-17.