Vulnerability Description
AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproject.php; kind_id, priority_id, project_id, status_id and title in action/addticket.php; and kind_id and status_id in reports.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Abisoftgt | Ticketly | 1.0 |
Related Weaknesses (CWE)
References
- https://hackpuntes.com/cve-2018-18923-ticketly-1-0-multiples-sql-injections/ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/45902/ExploitThird Party AdvisoryVDB Entry
- https://hackpuntes.com/cve-2018-18923-ticketly-1-0-multiples-sql-injections/ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/45902/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2018-18923?
CVE-2018-18923 is a vulnerability with a CVSS score of 9.8 (CRITICAL). AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproject.php; kind_id, priority_id, project_id, status_i...
How severe is CVE-2018-18923?
CVE-2018-18923 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-18923?
Check the references section above for vendor advisories and patch information. Affected products include: Abisoftgt Ticketly.