CVE-2023-7337

HIGH NUCLEI

JS Help Desk < 2.8.2 - Unauthenticated SQL Injection via Cookie

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-7337. PoCs published by Sechunt3r. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2023-7337, an SQL injection vulnerability in JS Help Desk WordPress plugin (version 2.8.2). The exploit leverages the 'js-support-ticket-token-tkstatus' cookie to inject malicious SQL payloads, confirmed via time-based blind SQLi techniques.

Description

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in version 2.8.2 due to an incomplete fix for CVE-2023-50839 where a second sink was left with insufficient escaping on the user supplied values and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Exploits (1)

github WORKING POC
by Sechunt3r · shellpoc
https://github.com/Sechunt3r/CVE-POCs/tree/main/CVE-2023-7337

This repository contains a functional exploit for CVE-2023-7337, an SQL injection vulnerability in JS Help Desk WordPress plugin (version 2.8.2). The exploit leverages the 'js-support-ticket-token-tkstatus' cookie to inject malicious SQL payloads, confirmed via time-based blind SQLi techniques.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: JS Help Desk WordPress plugin <= 2.8.2
No auth needed
Prerequisites: WordPress site with vulnerable JS Help Desk plugin installed
devstral-2 · analyzed Mar 06, 2026 Full analysis →

Nuclei Templates (1)

JS Help Desk <= 2.8.2 - SQL Injection
CRITICALVERIFIEDby Shivam Kamboj

Scores

CVSS v3 7.5
EPSS 0.0132
EPSS Percentile 67.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
rabilal/JS Help Desk – AI-Powered Support & Ticketing System < 2.8.2
Published Mar 04, 2026
Tracked Since Mar 04, 2026