Show filters
83 Total Results
Displaying 11-20 of 83
Sort by:
Attacker Value
Unknown

CVE-2023-25350

Disclosure Date: March 24, 2023 (last updated February 23, 2025)
Faveo Helpdesk 1.0-1.11.1 is vulnerable to SQL Injection. When the user logs in through the login box, he has no judgment on the validity of the user's input data. The parameters passed from the front end to the back end are controllable, which will lead to SQL injection.
Attacker Value
Unknown

CVE-2022-31400

Disclosure Date: June 13, 2022 (last updated October 07, 2023)
A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
Attacker Value
Unknown

CVE-2022-31398

Disclosure Date: June 13, 2022 (last updated October 07, 2023)
A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
Attacker Value
Unknown

CVE-2021-35254

Disclosure Date: March 25, 2022 (last updated October 07, 2023)
SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this input in the future.
Attacker Value
Unknown

CVE-2021-35232

Disclosure Date: December 22, 2021 (last updated September 17, 2024)
Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the database and leverage the vulnerability to steal the password hashes of the users or insert arbitrary data into the database.
Attacker Value
Unknown

CVE-2021-3994

Disclosure Date: December 01, 2021 (last updated October 07, 2023)
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Attacker Value
Unknown

CVE-2021-3950

Disclosure Date: November 19, 2021 (last updated October 07, 2023)
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Attacker Value
Unknown

CVE-2021-3945

Disclosure Date: November 13, 2021 (last updated October 07, 2023)
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Attacker Value
Unknown

CVE-2021-28814

Disclosure Date: June 11, 2021 (last updated February 22, 2025)
An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise the security of the software. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.4.
Attacker Value
Unknown

CVE-2019-16959

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.