Vulnerability Description
Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity of the user's input data. The parameters passed from the front end to the back end are controllable, which will lead to SQL injection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ladybirdweb | Faveo Helpdesk | >= 1.0, <= 1.11.1 |
Related Weaknesses (CWE)
References
- https://gist.github.com/Whitehat-Su/8402323c00ea93b4abc21ab9a372101eThird Party Advisory
- https://github.com/ladybirdweb/faveo-helpdesk/issues/7827ExploitIssue TrackingThird Party Advisory
- https://gist.github.com/Whitehat-Su/8402323c00ea93b4abc21ab9a372101eThird Party Advisory
- https://github.com/ladybirdweb/faveo-helpdesk/issues/7827ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2023-25350?
CVE-2023-25350 is a vulnerability with a CVSS score of 8.8 (HIGH). Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity of the user's input data. The parameters passed from the front...
How severe is CVE-2023-25350?
CVE-2023-25350 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25350?
Check the references section above for vendor advisories and patch information. Affected products include: Ladybirdweb Faveo Helpdesk.