logo

SysAid Helpdesk Pro – Blind SQL Injection

ID: a2468d2a-b565-59e2-a38d-99f77d3b8910

STIX ID: report--a2468d2a-b565-59e2-a38d-99f77d3b8910

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2025-12-02

Date Updated: 2026-08-01

ADMIRALTY:B6
...
...

SysAid Helpdesk v8.5.04 Pro contains multiple authenticated blind SQL injection flaws in the administrator interface (examples: `/AssetManagementList.jsp` parameter `computerID`, `AssetManagementChart.jsp` `group1`, `/genericreport` POST parameters `assetID`, `customSQL`, `groupFilter`, and `CIEdit.jsp` POST parameters). A PoC using sqlmap demonstrates extraction of the `ilient` database and its tables; the issue was fixed in version `8.5.08`.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.