Show filters
65 Total Results
Displaying 21-30 of 65
Sort by:
Attacker Value
Unknown
CVE-2024-44011
Disclosure Date: October 05, 2024 (last updated October 05, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Ticket Ultra WP Ticket Ultra Help Desk & Support Plugin allows PHP Local File Inclusion.This issue affects WP Ticket Ultra Help Desk & Support Plugin: from n/a through 1.0.5.
0
Attacker Value
Unknown
CVE-2024-7094
Disclosure Date: August 13, 2024 (last updated August 13, 2024)
The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the style.php file, along with missing capability checks. This makes it possible for unauthenticated attackers to execute code on the server. This issue was partially patched in 2.8.6 when the code injection issue was resolved, and fully patched in 2.8.7 when the missing authorization and cross-site request forgery protection was added.
0
Attacker Value
Unknown
CVE-2024-31273
Disclosure Date: June 09, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.3.
0
Attacker Value
Unknown
CVE-2023-25444
Disclosure Date: May 17, 2024 (last updated May 17, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Using Malicious Files.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.7.
0
Attacker Value
Unknown
CVE-2022-47151
Disclosure Date: April 17, 2024 (last updated April 17, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.
0
Attacker Value
Unknown
CVE-2022-46839
Disclosure Date: January 05, 2024 (last updated January 12, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.
0
Attacker Value
Unknown
CVE-2023-50839
Disclosure Date: December 28, 2023 (last updated January 05, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.1.
0
Attacker Value
Unknown
CVE-2021-43609
Disclosure Date: November 09, 2023 (last updated November 17, 2023)
An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort parameter. This can be leveraged to leak local files from the host system, leading to remote code execution (RCE) through deserialization of malicious data.
0
Attacker Value
Unknown
CVE-2023-1019
Disclosure Date: May 15, 2023 (last updated October 08, 2023)
The Help Desk WP WordPress plugin through 1.2.0 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2023-1125
Disclosure Date: May 02, 2023 (last updated October 08, 2023)
The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.
0