Show filters
65 Total Results
Displaying 31-40 of 65
Sort by:
Attacker Value
Unknown
CVE-2021-33353
Disclosure Date: March 08, 2023 (last updated October 08, 2023)
Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting.
0
Attacker Value
Unknown
CVE-2021-33352
Disclosure Date: March 08, 2023 (last updated October 08, 2023)
An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field.
0
Attacker Value
Unknown
CVE-2021-33351
Disclosure Date: March 08, 2023 (last updated October 08, 2023)
Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field.
0
Attacker Value
Unknown
CVE-2022-46842
Disclosure Date: February 02, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in JS Help Desk plugin <= 2.7.1 versions.
0
Attacker Value
Unknown
CVE-2022-40325
Disclosure Date: September 11, 2022 (last updated February 24, 2025)
SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262.
0
Attacker Value
Unknown
CVE-2022-40324
Disclosure Date: September 11, 2022 (last updated February 24, 2025)
SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258.
0
Attacker Value
Unknown
CVE-2022-40323
Disclosure Date: September 11, 2022 (last updated February 24, 2025)
SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241.
0
Attacker Value
Unknown
CVE-2022-40322
Disclosure Date: September 11, 2022 (last updated February 24, 2025)
SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579.
0
Attacker Value
Unknown
CVE-2021-35251
Disclosure Date: March 07, 2022 (last updated February 23, 2025)
Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details about the Web Help Desk installation.
0
Attacker Value
Unknown
CVE-2021-35243
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method requests that the origin server removes the association between the target resource and its current functionality. Improper use of these methods may lead to a loss of integrity.
0