An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort parameter. This can be leveraged to leak local files from the host system, leading to remote code execution (RCE) through deserialization of malicious data.
References
Link | Resource |
---|---|
https://community.spiceworks.com/blogs/help-desk-server-release-notes/3610-1-3-2-1-3-3 | Release Notes |
https://github.com/d5sec/CVE-2021-43609-POC | Third Party Advisory |
https://www.linkedin.com/pulse/cve-2021-43609-write-up-division5-security-4lgwe | Exploit Third Party Advisory |
https://community.spiceworks.com/blogs/help-desk-server-release-notes/3610-1-3-2-1-3-3 | Release Notes |
https://github.com/d5sec/CVE-2021-43609-POC | Third Party Advisory |
https://www.linkedin.com/pulse/cve-2021-43609-write-up-division5-security-4lgwe | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 06:29
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.9 |
References | () https://community.spiceworks.com/blogs/help-desk-server-release-notes/3610-1-3-2-1-3-3 - Release Notes | |
References | () https://github.com/d5sec/CVE-2021-43609-POC - Third Party Advisory | |
References | () https://www.linkedin.com/pulse/cve-2021-43609-write-up-division5-security-4lgwe - Exploit, Third Party Advisory |
16 Nov 2023, 14:09
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CPE | cpe:2.3:a:spiceworks:help_desk_server:*:*:*:*:*:*:*:* | |
CWE | CWE-89 | |
References | () https://www.linkedin.com/pulse/cve-2021-43609-write-up-division5-security-4lgwe - Exploit, Third Party Advisory | |
References | () https://github.com/d5sec/CVE-2021-43609-POC - Third Party Advisory | |
References | () https://community.spiceworks.com/blogs/help-desk-server-release-notes/3610-1-3-2-1-3-3 - Release Notes | |
First Time |
Spiceworks help Desk Server
Spiceworks |
09 Nov 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-09 00:15
Updated : 2024-11-21 06:29
NVD link : CVE-2021-43609
Mitre link : CVE-2021-43609
CVE.ORG link : CVE-2021-43609
JSON object : View
Products Affected
spiceworks
- help_desk_server
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')