Description
WBiz Desk 1.2 contains a SQL injection vulnerability that allows non-admin users to manipulate database queries through the 'tk' parameter in ticket.php. Attackers can inject crafted SQL statements using UNION-based techniques to extract sensitive database information by sending malformed requests to the ticket endpoint.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
h4ck3r - Faisal Albuloushi
References
www.exploit-db.com/exploits/51451 (ExploitDB-51451)
www.codester.com/...sk-simple-and-effective-help-desk-system (Official Product Homepage)
www.vulncheck.com/...n-vulnerability-via-ticketphp-parameter (VulnCheck Advisory: WBiz Desk 1.2 SQL Injection Vulnerability via ticket.php Parameter)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.