PT-2023-22666 · Unknown · Helpdezk Community

David Utón Amaya

+1

·

Published

2023-10-04

·

Updated

2023-10-05

·

CVE-2023-3038

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HelpDezk Community version 1.1.10
Description The issue is related to a SQL injection vulnerability that could allow a remote attacker to send a specially crafted SQL query to the rows parameter of the "jsonGrid route" and extract all the information stored in the application.
Recommendations For version 1.1.10, consider disabling access to the "jsonGrid route" until a patch is available. Restrict the use of the rows parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-3038

Affected Products

Helpdezk Community