CVE-2023-33706
24.11.2023, 02:15
SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp.Enginsight
Vendor | Product | Version |
---|---|---|
sysaid | sysaid | 𝑥 < 23.2.15 |
sysaid | sysaid | 𝑥 < 23.2.50 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration