Unrated severityNVD Advisory· Published Nov 8, 2021· Updated Aug 3, 2024
CVE-2021-28022
CVE-2021-28022
Description
Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- ServiceTonic/Helpdesk softwaredescription
Patches
Vulnerability mechanics
References
2- www.servicetonic.commitrex_refsource_MISC
- www.srlabs.de/bites/chaining-three-zero-day-exploits-in-itsm-software-servicetonic-for-remote-code-executionmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.