CVE-2023-33706

Publication date

2023-11-24 00:00:00

Family

mitre

State

PUBLISHED

Description

SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp.