Newsletter
REAL HACKER NEWS
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO
No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO
No Result
View All Result
REAL HACKER NEWS
No Result
View All Result
Home APPLICATIONS

Researchers Reported Critical SQLi and Access Flaws in Zendesk Analytics Service

Real Hacker Staff by Real Hacker Staff
November 21, 2022
in APPLICATIONS
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Related articles

Why can’t I use my iPhone as a webcam on my Apple TV?

Why can’t I use my iPhone as a webcam on my Apple TV?

April 1, 2023
Happy Birthday Apple – these are iMore’s favorite products of all time

Happy Birthday Apple – these are iMore’s favorite products of all time

April 1, 2023


Cybersecurity researchers have disclosed particulars of now-patched flaws in Zendesk Discover that would have been exploited by an attacker to realize unauthorized entry to data from buyer accounts which have the characteristic turned on.

“Earlier than it was patched, the flaw would have allowed menace actors to entry conversations, e-mail addresses, tickets, feedback, and different data from Zendesk accounts with Discover enabled,” Varonis stated in a report shared with The Hacker Information.

The cybersecurity agency stated there was no proof to recommend that the problems have been actively exploited in real-world assaults. No motion is required on the a part of the shoppers.

Zendesk Discover is a reporting and analytics answer that enables organizations to “view and analyze key details about your clients, and your help assets.”

Zendesk Analytics Service

Based on the safety software program firm, exploitation of the shortcoming first requires an attacker to register for the ticketing service of its sufferer’s Zendesk account as a brand new exterior consumer, a characteristic that is probably enabled by default to permit end-users to submit help tickets.

The vulnerability pertains to an SQL injection in its GraphQL API that might be abused to exfiltrate all data saved within the database as an admin consumer, together with e-mail addresses, tickets, and conversations with dwell brokers.

A second flaw issues a logic entry situation related to a question execution API, which was configured to run the queries with out checking if the “consumer” making the decision had sufficient permission to take action.

“This meant {that a} newly created end-user might invoke this API, change the question, and steal knowledge from any desk within the goal Zendesk account’s RDS, no SQLi required,”

Varonis stated the problems have been disclosed to Zendesk on August 30, following which the weaknesses have been rectified by the corporate on September 8, 2022.





Source link

Tags: accessAnalyticsCriticalFlawsReportedresearchersserviceSQLiZendesk
Share76Tweet47

Related Posts

Why can’t I use my iPhone as a webcam on my Apple TV?

Why can’t I use my iPhone as a webcam on my Apple TV?

by Real Hacker Staff
April 1, 2023
0

OK, so hear me out. Wouldn't it be pretty cool if you could use your iPhone as a webcam for...

Happy Birthday Apple – these are iMore’s favorite products of all time

Happy Birthday Apple – these are iMore’s favorite products of all time

by Real Hacker Staff
April 1, 2023
0

Today, on April 1, back in 1976, Apple was founded by Steve Jobs and Steve Wozniak, which eventually led to...

Microsoft Fixes New Azure AD Vulnerability Impacting Bing Search and Major Apps

Microsoft Fixes New Azure AD Vulnerability Impacting Bing Search and Major Apps

by Real Hacker Staff
April 1, 2023
0

î ‚Apr 01, 2023î „Ravie LakshmananAzure / Active Directory Microsoft has patched a misconfiguration issue impacting the Azure Active Directory (AAD) identity...

Cacti, Realtek, and IBM Aspera Faspex Vulnerabilities Under Active Exploitation

by Real Hacker Staff
April 1, 2023
0

î ‚Apr 01, 2023î „Ravie LakshmananCyber Attack / Vulnerability Critical security flaws in Cacti, Realtek, and IBM Aspera Faspex are being exploited...

Millions of Sites at Risk!

Millions of Sites at Risk!

by Real Hacker Staff
April 1, 2023
0

î ‚Apr 01, 2023î „Ravie LakshmananWeb Security / Cyber Threat Unknown threat actors are actively exploiting a recently patched security vulnerability in...

Load More
  • Trending
  • Comments
  • Latest

eSIMs Will Transform the Way You Think About Mobile Data and Security

March 7, 2023

XMOS Launches XVF3800 High-Performance Voice Processor for Enterprise and Consumer Voice Conferencing Platforms

March 7, 2023

Sennheiser Starts Shipping EW-DX Digital Wireless Microphone Series

November 22, 2022

Chinese Hackers Using Russo-Ukrainian War Decoys to Target APAC and European Entities

December 7, 2022

Hello world!

0
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Virgin Orbit runs low on cash, ByteDance pushes a TikTok replacement, and Canoo settles with the SEC

Virgin Orbit runs low on cash, ByteDance pushes a TikTok replacement, and Canoo settles with the SEC

April 1, 2023
Poll: Which upcoming foldable phone are you looking forward to in 2023?

Poll: Which upcoming foldable phone are you looking forward to in 2023?

April 1, 2023
It’s April Fools’ Day, Here Are The Best Gaming Gags We’ve Seen

It’s April Fools’ Day, Here Are The Best Gaming Gags We’ve Seen

April 1, 2023
Save up to 35 percent on Logitech’s G PRO X Gaming Headset and more

Save up to 35 percent on Logitech’s G PRO X Gaming Headset and more

April 1, 2023

Recent News

Virgin Orbit runs low on cash, ByteDance pushes a TikTok replacement, and Canoo settles with the SEC

Virgin Orbit runs low on cash, ByteDance pushes a TikTok replacement, and Canoo settles with the SEC

April 1, 2023
Poll: Which upcoming foldable phone are you looking forward to in 2023?

Poll: Which upcoming foldable phone are you looking forward to in 2023?

April 1, 2023

Categories

  • APPLICATIONS
  • AUDIO
  • CAMERA
  • COMPUTERS
  • GAMING
  • LAPTOP
  • REVIEWS
  • SECURITY
  • SMARTPHONES
  • Uncategorized
REAL HACKER NEWS

We bring you the best news on Internet new gadgets hacking and technology from around the world

  • Contact
  • Cookie Privacy Policy
  • Terms and Conditions
  • Privacy Policy
  • Disclaimer
  • DMCA

© 2003 Real Hacker News

No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO

© 2003 Real Hacker News

Go to mobile version