VYPR

Help Desk Server

by Spiceworks

CVEs (1)

  • CVE-2021-43609CriNov 9, 2023
    risk 0.65cvss 9.9epss 0.02

    An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort…