CVE-2017-13068: SQL Injection
Published Oct 6, 2017
·Updated
QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack.
Affected Software
1 affected component
QNAP Qts Helpdesk<=1.1.12
Event History
Oct 5, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-13068?
CVE-2017-13068 is considered a high-severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2017-13068?
To fix CVE-2017-13068, update the QTS Helpdesk application to version 1.1.13 or later.
3
What type of attack does CVE-2017-13068 allow?
CVE-2017-13068 allows remote attackers to perform SQL injection attacks on the QTS Helpdesk application.
4
Is authentication required to exploit CVE-2017-13068?
No, exploitation of CVE-2017-13068 does not require any privileges or authentication.
5
Which versions of QTS Helpdesk are affected by CVE-2017-13068?
CVE-2017-13068 affects all versions of QTS Helpdesk up to and including version 1.1.12.