Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WBiz Desk 1.2 contains a SQL injection vulnerability that allows non-admin users to manipulate database queries through the 'tk' parameter in ticket.php. Attackers can inject crafted SQL statements using UNION-based techniques to extract sensitive database information by sending malformed requests to the ticket endpoint. | |
| Title | WBiz Desk 1.2 SQL Injection Vulnerability via ticket.php Parameter | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:07:54.856Z
Reserved: 2025-12-16T19:22:09.997Z
Link: CVE-2023-53935
Updated: 2025-12-18T21:04:08.876Z
Status : Deferred
Published: 2025-12-18T20:15:51.683
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-53935
No data.
OpenCVE Enrichment
No data.