Traq 3.7.1 tickets sql injection

A vulnerability, which was classified as critical, has been found in Traq 3.7.1. Affected by this issue is some functionality of the file tickets?search. The manipulation with an unknown input leads to a sql injection vulnerability. Using CWE to declare the problem leads to CWE-89. Impacted is confidentiality, integrity, and availability. An attacker might be able inject and/or alter existing SQL statements which would influence the database exchange.

The weakness was presented 02/11/2019. This vulnerability is handled as CVE-2018-20779 since 02/10/2019. The attack may be launched remotely. Technical details are known, but there is no available exploit. The structure of the vulnerability defines a possible price range of USD $0-$5k at the moment (estimation calculated on 02/11/2019).

There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.

