Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Use of user input in raw SQL queries in vsDesk leading to blind SQL injection
Vulnerability Description
The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
N/A
Vulnerability Title
vsDesk 安全漏洞
Vulnerability Description
vsDesk是vsDesk组织的一款服务器与网络管理设备。 vsDesk 11.06.02版本存在安全漏洞,该漏洞源于应用程序组件不安全地处理用户提供的参数并将其传递到SQL查询中,可能导致盲SQL注入,从而暴露数据库内容或导致应用程序无响应。
CVSS Information
N/A
Vulnerability Type
N/A