SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Oneorzero_helpdesk | Oneorzero | 1.4_rc4 (including) | 1.4_rc4 (including) |