Show filters
65 Total Results
Displaying 41-50 of 65
Sort by:
Attacker Value
Unknown
CVE-2021-24741
Disclosure Date: September 20, 2021 (last updated February 23, 2025)
The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.
0
Attacker Value
Unknown
CVE-2021-32076
Disclosure Date: August 20, 2021 (last updated February 23, 2025)
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.
0
Attacker Value
Unknown
CVE-2019-16961
Disclosure Date: January 15, 2021 (last updated February 22, 2025)
SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.
0
Attacker Value
Unknown
CVE-2019-16954
Disclosure Date: January 06, 2021 (last updated February 22, 2025)
SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.
0
Attacker Value
Unknown
CVE-2019-16960
Disclosure Date: January 04, 2021 (last updated February 22, 2025)
SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.
0
Attacker Value
Unknown
CVE-2019-16956
Disclosure Date: January 04, 2021 (last updated February 22, 2025)
SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.
0
Attacker Value
Unknown
CVE-2019-16958
Disclosure Date: December 01, 2020 (last updated February 22, 2025)
Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.
0
Attacker Value
Unknown
CVE-2013-2625
Disclosure Date: November 27, 2019 (last updated November 27, 2024)
An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified
0
Attacker Value
Unknown
CVE-2018-21002
Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
0
Attacker Value
Unknown
CVE-2018-18373
Disclosure Date: October 17, 2018 (last updated November 27, 2024)
In the Schiocco "Support Board - Chat And Help Desk" plugin 1.2.3 for WordPress, a Stored XSS vulnerability has been discovered in file upload areas in the Chat and Help Desk sections via the msg parameter in a /wp-admin/admin-ajax.php sb_ajax_add_message action.
0