CVE-2018-18923
AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproject.php; kind_id, priority_id, project_id, status_id and title in action/addticket.php; and kind_id and…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproject.php; kind_id, priority_id, project_id, status_id and title in action/addticket.php; and kind_id and status_id in reports.php.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.21% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- abisoftgt/ticketly
- Source
- cve@mitre.org
References
- https://hackpuntes.com/cve-2018-18923-ticketly-1-0-multiples-sql-injections/Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/45902/Exploit, Third Party Advisory, VDB Entry
- https://hackpuntes.com/cve-2018-18923-ticketly-1-0-multiples-sql-injections/Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/45902/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.