This software has multiple critical security issues!!
- Username
- Email ID
- Ticket Subject
- Ticket Purpose
- And more...
- Any valid user can create new users (of any privilege)
- /API/Ticket/updateTicket
- /tabler/list_users
More Information
I wrote a blog post about these vulnerabilities with pictures and more in-depth explanations, please see for more information:
http://blog.slicklabz.com/bugbounty/opensource/tikaj_helpdesk
-CRFSlick
This software has multiple critical security issues!!
Stored XSS (https://portswigger.net/web-security/cross-site-scripting)
Privilege Escalation (https://portswigger.net/web-security/access-control)
SQL Injection (https://portswigger.net/web-security/sql-injection)
More Information
I wrote a blog post about these vulnerabilities with pictures and more in-depth explanations, please see for more information:
http://blog.slicklabz.com/bugbounty/opensource/tikaj_helpdesk
-CRFSlick