Joomla · Helpdesk Pro · CVE-2015-4073
**Name of the Vulnerable Software and Affected Versions**
Helpdesk Pro plugin versions prior to 1.4.0 for Joomla!
**Description**
The issue allows remote attackers to execute arbitrary SQL commands via the `ticket code` or `email` parameter. Additionally, remote authenticated users can execute arbitrary SQL commands via the `filter order` parameter.
**Recommendations**
For versions prior to 1.4.0, update to version 1.4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the `ticket code`, `email`, and `filter order` parameters to minimize the risk of exploitation.