SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp.
| Software | From | Fixed in |
|---|---|---|
| sysaid / sysaid | - | 23.2.50 |
| sysaid / sysaid | - | 23.2.15 |