Vulnerability Description
An issue was discovered in HelpDeskZ 1.0.2. The feature to auto-login a user, via the RememberMe functionality, is prone to SQL injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Evolutionscript | Helpdeskz | 1.0.2 |
Related Weaknesses (CWE)
References
- https://cds.thalesgroup.com/en/tcs-cert/CVE-2020-26546
- https://excellium-services.com/cert-xlm-advisory/CVE-2020-26546/Third Party Advisory
- https://excellium-services.com/cert-xlm-advisory/CVE-2020-26546/Third Party Advisory
FAQ
What is CVE-2020-26546?
CVE-2020-26546 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in HelpDeskZ 1.0.2. The feature to auto-login a user, via the RememberMe functionality, is prone to SQL injection. NOTE: This vulnerability only affects products that are no lo...
How severe is CVE-2020-26546?
CVE-2020-26546 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26546?
Check the references section above for vendor advisories and patch information. Affected products include: Evolutionscript Helpdeskz.