CVE-2017-14145: Helpdezk

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function.

Affected products

Published 2017-09-05. Last modified 2026-06-17.