We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user. When an authenticated user submits a ticket, the request can be intercepted and subsequently modified by using a proxy. The ticket requester can be changed from the original requester to another user in the same application, which the application then accepts.
Reserved 2024-12-03 | Published 2024-12-04 | Updated 2024-12-04 | Assigner GridwareCWE-472: External Control of Assumed-Immutable Web Parameter
CWE-837 Improper Enforcement of a Single, Unique Action
Harrison Daley
helpcenter.issuetrak.com/home/2340-issuetrak-release-notes
Support options