Show filters
83 Total Results
Displaying 31-40 of 83
Sort by:
Attacker Value
Unknown

CVE-2019-20002

Disclosure Date: April 27, 2020 (last updated February 21, 2025)
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.
Attacker Value
Unknown

CVE-2018-0728

Disclosure Date: December 04, 2019 (last updated November 27, 2024)
This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.
Attacker Value
Unknown

CVE-2017-18486

Disclosure Date: August 09, 2019 (last updated November 27, 2024)
Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The shared secret can be used to escalate privileges by forging new tokens for any user. These tokens can be used to automatically log in as the affected user.
0
Attacker Value
Unknown

CVE-2018-0714

Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run arbitrary commands in the compromised application.
0
Attacker Value
Unknown

CVE-2017-13068

Disclosure Date: October 06, 2017 (last updated November 26, 2024)
QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack.
0
Attacker Value
Unknown

CVE-2017-14320

Disclosure Date: September 21, 2017 (last updated November 26, 2024)
Mirasvit Helpdesk MX before 1.5.3 might allow remote attackers to execute arbitrary code by leveraging failure to filter uploaded files.
0
Attacker Value
Unknown

CVE-2017-14321

Disclosure Date: September 21, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the administrative interface in Mirasvit Helpdesk MX before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) customer name or (2) subject in a ticket.
0
Attacker Value
Unknown

CVE-2015-4074

Disclosure Date: September 20, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.
0
Attacker Value
Unknown

CVE-2015-4072

Disclosure Date: September 20, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to name and message.
0
Attacker Value
Unknown

CVE-2015-4073

Disclosure Date: September 20, 2017 (last updated November 26, 2024)
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the filter_order parameter.
0