CVE-2021-28022

Publication date

2021-11-08 14:28:50

Family

mitre

State

PUBLISHED

Description

Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries.