SQL injection in Track-It! - #VU65356
Published: July 15, 2022
Track-It!
BMC Software
Description
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data within the GetPopupSubQueryDetails endpoint. A remote user can send a specially crafted request to the affected application and gain access to sensitive information on the target system.