Show filters
65 Total Results
Displaying 41-50 of 65
Sort by:
Attacker Value
Unknown

CVE-2021-24741

Disclosure Date: September 20, 2021 (last updated February 23, 2025)
The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.
Attacker Value
Unknown

CVE-2021-32076

Disclosure Date: August 20, 2021 (last updated February 23, 2025)
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.
Attacker Value
Unknown

CVE-2019-16961

Disclosure Date: January 15, 2021 (last updated February 22, 2025)
SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.
Attacker Value
Unknown

CVE-2019-16954

Disclosure Date: January 06, 2021 (last updated February 22, 2025)
SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.
Attacker Value
Unknown

CVE-2019-16960

Disclosure Date: January 04, 2021 (last updated February 22, 2025)
SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.
Attacker Value
Unknown

CVE-2019-16956

Disclosure Date: January 04, 2021 (last updated February 22, 2025)
SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.
Attacker Value
Unknown

CVE-2019-16958

Disclosure Date: December 01, 2020 (last updated February 22, 2025)
Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.
Attacker Value
Unknown

CVE-2013-2625

Disclosure Date: November 27, 2019 (last updated November 27, 2024)
An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified
Attacker Value
Unknown

CVE-2018-21002

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
0
Attacker Value
Unknown

CVE-2018-18373

Disclosure Date: October 17, 2018 (last updated November 27, 2024)
In the Schiocco "Support Board - Chat And Help Desk" plugin 1.2.3 for WordPress, a Stored XSS vulnerability has been discovered in file upload areas in the Chat and Help Desk sections via the msg parameter in a /wp-admin/admin-ajax.php sb_ajax_add_message action.
0