SQL Injection Vulnerability in QNAP Helpdesk Application
CVE-2017-13068
What is CVE-2017-13068?
The vulnerability in QNAP's Helpdesk application allows remote attackers to exploit an SQL injection flaw, enabling them to gain unauthorized access to sensitive application information. This type of attack does not require any authentication, making it particularly dangerous as it can be initiated without user privileges. QNAP has since released a patch to mitigate this vulnerability, but users are advised to ensure they are running the latest version of the software to protect against potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
QNAP Helpdesk APP QTS Helpdesk versions 1.1.12 and earlier
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved