CVE-2017-13068

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
06/10/2017
Last modified:
20/04/2025

Description

QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qnap:qts_helpdesk:*:*:*:*:*:*:*:* 1.1.12 (including)