9.8
CVSSv3

CVE-2018-18923

Published: 13/12/2018 Updated: 02/01/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproject.php; kind_id, priority_id, project_id, status_id and title in action/addticket.php; and kind_id and status_id in reports.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

abisoftgt ticketly 1.0

Exploits

# Exploit Title: Ticketly 10 – Multiple SQL Injection # Exploit Author: Javier Olmedo # Website: hackpuntescom # Date: 2018-11-19 # Google Dork: N/A # Vendor: Abisoft (abisoftgtnet) # Software Link: abisoftgtnet/software/6/sistema-de-tickets-y-soporte-con-php-y-mysql # Affected Version: 10 # Patched Version: unpatched ...
Ticketly version 10 suffers from a remote SQL injection vulnerability ...