CVE-2023-25350

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-25350
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25350.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-25350
Published
2023-03-24T20:15:15.403Z
Modified
2025-11-20T12:13:13.422237Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity of the user's input data. The parameters passed from the front end to the back end are controllable, which will lead to SQL injection.

References

Affected packages

Git / github.com/ladybirdweb/faveo-helpdesk

Affected ranges

Type
GIT
Repo
https://github.com/ladybirdweb/faveo-helpdesk
Events

Affected versions

1.*

1.0.2.1
1.0.3

v.*

v.1.9.5

v1.*

v1.0.0
v1.0.1
v1.0.2
v1.0.2.1
v1.0.3
v1.0.3.1
v1.0.3.2
v1.0.3.3
v1.0.3.4
v1.0.3.5
v1.0.4
v1.0.4.1
v1.0.4.2
v1.0.5
v1.0.5.1
v1.0.5.2
v1.0.5.3
v1.0.5.4
v1.0.5.5
v1.0.5.6
v1.0.5.7
v1.0.5.8
v1.0.6
v1.0.6.1
v1.0.6.10
v1.0.6.2
v1.0.6.4
v1.0.6.5
v1.0.6.6
v1.0.6.7
v1.0.6.8
v1.0.6.9
v1.0.7
v1.0.7.1
v1.0.7.2
v1.0.7.3
v1.0.7.4
v1.0.7.5
v1.0.7.6
v1.0.7.7
v1.0.7.8
v1.0.7.9
v1.0.8.0
v1.10
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.10.5
v1.10.6
v1.11.0
v1.11.1
v1.9.0
v1.9.1
v1.9.2
v1.9.3
v1.9.4
v1.9.6