Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Multiple Critical Security Vulnerabilites (XSS, Privilege Escalation, SQL Injection) #9

Open
ghost opened this issue Jan 15, 2021 · 4 comments

Comments

@ghost
Copy link

ghost commented Jan 15, 2021

This software has multiple critical security issues!!

Stored XSS (https://portswigger.net/web-security/cross-site-scripting)

  • Username
  • Email ID
  • Ticket Subject
  • Ticket Purpose
  • And more...

Privilege Escalation (https://portswigger.net/web-security/access-control)

  • Any valid user can create new users (of any privilege)

SQL Injection (https://portswigger.net/web-security/sql-injection)

  • /API/Ticket/updateTicket
  • /tabler/list_users

More Information

I wrote a blog post about these vulnerabilities with pictures and more in-depth explanations, please see for more information:
http://blog.slicklabz.com/bugbounty/opensource/tikaj_helpdesk

-CRFSlick

@eksha
Copy link
Member

eksha commented Jan 21, 2021

Hi,

Thank you for reporting the vulnerabilities. We would like to address them in future updates if the community is using them in production environment.

I want to appreciate the effort you have to taken to make a detailed report to address security issues in such small opensource project and keeping it secure.

Thank you for the effort.

@ddiaz2380
Copy link

I have the same problem, if a file is not attached, the comment is not refreshed ... but if you manually refresh the browser if you add it. Someone fix it?

@CMLCNL
Copy link

CMLCNL commented Apr 17, 2021

Has this been fixed? Thank you for. I liked your work very much. @eksha

@eksha
Copy link
Member

eksha commented Apr 21, 2021

@CMLCNL we have not been able to yet dedicate time on these issues. If someone would like to contribute, we would be very happy to accept PRs!

Please keep following this thread, we will try to soon expediate this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants