PT-2021-17711 · Servicetonic · Servicetonic Helpdesk

Published

2021-11-08

·

Updated

2021-11-09

·

CVE-2021-28022

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: ServiceTonic Helpdesk software versions prior to 9.0.35937
Description: The issue allows an attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries using blind SQL injection in the login form.
Recommendations: For versions prior to 9.0.35937, update to version 9.0.35937 or later to resolve the issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-28022

Affected Products

Servicetonic Helpdesk