CVE-2021-43609
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort parameter. This can be leveraged to leak local files from the host system, leading to remote code execution (RCE) through deserialization of malicious data.
Se descubrió un problema en Spiceworks Help Desk Server antes de la versión 1.3.3. Una vulnerabilidad de inyección Blind Boolean SQL dentro de la función order_by_for_ticket en app/models/reporting/database_query.rb permite a un atacante autenticado ejecutar comandos SQL arbitrarios a través del parámetro sort. Esto se puede aprovechar para filtrar archivos locales del sistema host, lo que lleva a la ejecución remota de código (RCE) mediante la deserialización de datos maliciosos.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2021-11-12 CVE Reserved
- 2023-11-08 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://community.spiceworks.com/blogs/help-desk-server-release-notes/3610-1-3-2-1-3-3 | Release Notes |
URL | Date | SRC |
---|---|---|
https://github.com/d5sec/CVE-2021-43609-POC | 2024-09-17 | |
https://www.linkedin.com/pulse/cve-2021-43609-write-up-division5-security-4lgwe | 2024-09-17 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Spiceworks Search vendor "Spiceworks" | Help Desk Server Search vendor "Spiceworks" for product "Help Desk Server" | < 1.3.3 Search vendor "Spiceworks" for product "Help Desk Server" and version " < 1.3.3" | - |
Affected
|