Vulnerability Description
WBiz Desk 1.2 contains a SQL injection vulnerability that allows non-admin users to manipulate database queries through the 'tk' parameter in ticket.php. Attackers can inject crafted SQL statements using UNION-based techniques to extract sensitive database information by sending malformed requests to the ticket endpoint.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://www.codester.com/items/5641/wbiz-desk-simple-and-effective-help-desk-sys
- https://www.exploit-db.com/exploits/51451
- https://www.vulncheck.com/advisories/wbiz-desk-sql-injection-vulnerability-via-t
FAQ
What is CVE-2023-53935?
CVE-2023-53935 is a vulnerability with a CVSS score of 5.4 (MEDIUM). WBiz Desk 1.2 contains a SQL injection vulnerability that allows non-admin users to manipulate database queries through the 'tk' parameter in ticket.php. Attackers can inject crafted SQL statements us...
How severe is CVE-2023-53935?
CVE-2023-53935 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-53935?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.