PT-2018-14723 · Abisoft · Abisoft Ticketly

Javier Olmedo

·

Publicado

2018-12-13

·

Atualizado

2019-01-02

·

CVE-2018-18923

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AbiSoft Ticketly version 1.0
Description The issue affects AbiSoft Ticketly through multiple SQL Injection vulnerabilities. These vulnerabilities are found in the parameters name, category id, and description in the "action/addproject.php" endpoint, kind id, priority id, project id, status id, and title in the "action/addticket.php" endpoint, and kind id and status id in the "reports.php" endpoint.
Recommendations For AbiSoft Ticketly version 1.0, as a temporary workaround, consider restricting access to the vulnerable endpoints "action/addproject.php", "action/addticket.php", and "reports.php" to minimize the risk of exploitation. Avoid using the parameters name, category id, description, kind id, priority id, project id, status id, and title in the affected endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18923

Produtos afetados

Abisoft Ticketly