High severity7.5NVD Advisory· Published Nov 8, 2021· Updated Jun 17, 2026
CVE-2021-28022
CVE-2021-28022
Description
Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- ServiceTonic/Helpdesk softwaredescription
- Range: <9.0.35937
Patches
Vulnerability mechanics
References
2- www.srlabs.de/bites/chaining-three-zero-day-exploits-in-itsm-software-servicetonic-for-remote-code-executionnvdExploitThird Party Advisory
- www.servicetonic.comnvdProduct
News mentions
0No linked articles in our index yet.