CVE-2014-100035
LicensePal ArcticDesk < 1.2.4 - SQL Injection in Ticket Grid
Title source: llmDescription
SQL injection vulnerability in the ticket grid in the admin interface in LicensePal ArcticDesk before 1.2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
http://www.arcticdesk.com/support/announcements/arcticdesk-v1-2-5-maintenance-release-18.html
Scores
EPSS
0.0118
EPSS Percentile
64.3%
Details
CWE
CWE-89
Status
published
Products (1)
licensepal/arcticdesk
< 1.2.4
Published
Jan 13, 2015
Tracked Since
Feb 18, 2026