First published: Fri Aug 15 2008(Updated: )
SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and earlier allows remote authenticated users to execute arbitrary SQL commands via the customfieldlinkid parameter in a delcflink action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kayako SupportSuite | =3.10.00 | |
Kayako SupportSuite | =3.11.01 | |
Kayako SupportSuite | <=3.20.02 | |
Kayako SupportSuite | =3.11.00 | |
Kayako SupportSuite | =3.10.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.