WBiz Desk 1.2 SQL Injection Vulnerability via ticket.php Parameter
Vulnerability Description
WBiz Desk 1.2 contains a SQL injection vulnerability that allows non-admin users to manipulate database queries through the 'tk' parameter in ticket.php. Attackers can inject crafted SQL statements using UNION-based techniques to extract sensitive database information by sending malformed requests to the ticket endpoint.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-53935
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- h4ck3r - Faisal Albuloushi
Affected Vendor
Codester
View all reports →