Description
|
|
Brandon Perry has reported some vulnerabilities in InvGate Service Desk, which can be exploited by malicious users to conduct SQL injection attacks.
Certain input related to breakingnew_id, incident_id, author_id, and default_filter is not properly sanitised before being used in some SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
Successful exploitation requires the end-user role.
The vulnerabilities are reported in version 4.2.36. Other versions may also be affected.
|