Open ISES Project
- <= 3.30A
A SQL injection vulnerability has been identified in the Open ISES Project version 3.30A. This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ticket_id parameter. Exploitation involves sending GET requests to add_facnote.php with crafted SQL payloads, which can be used to extract sensitive database information, including version details and other data.
Exploitation of this vulnerability allows for arbitrary SQL execution, which could lead to unauthorized data access or manipulation within the database.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.