9.8
CVSSv3

CVE-2015-4073

Published: 20/09/2017 Updated: 22/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin prior to 1.4.0 for Joomla! allow remote malicious users to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the filter_order parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

helpdesk pro project helpdesk pro

Exploits

Document Title ============== Joomla! plugin Helpdesk Pro < 140 Reported By =========== Simon Rawet from Outpost24 Kristian Varnai from Outpost24 Gregor Mynarsky from Outpost24 wwwoutpost24com/ For full details, see; wwwoutpost24com/outpost24-has-found-critical-vulnerabilities-in-joomla-helpdesk-pro/ Tested on ========= ...
Joomla Helpdesk Pro versions prior to 140 suffers from cross site scripting, local file disclosure, remote file upload, remote SQL injection, and insecure direct object reference vulnerabilities ...