Description
|
|
Two vulnerabilities have been reported in Free Help Desk, which can be exploited by malicious users to conduct SQL injection attacks and by malicious people to conduct cross-site request forgery attacks.
1) The application's web interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to e.g. add an administrator by tricking a logged in administrator into visiting a malicious web site.
This vulnerability is reported in version 1.1g. Other versions may also be affected.
2) Certain unspecified input is not properly sanitised before being used in a SQL query. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
This vulnerability is reported in versions 1.1a and prior.
|