Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NDefault status
unknown
Any version
affected
Description
Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version
References
nav1n.medium.com/...on-in-vision-helpdesk-tools-a83dfc27f3ab
nav1n.medium.com/...on-in-vision-helpdesk-tools-a83dfc27f3ab
www.visionhelpdesk.com/...5-7-0-stable-version-released.html