Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2024-2078

Disclosure Date: March 01, 2024 (last updated March 02, 2024)
A Cross-Site Scripting (XSS) vulnerability has been found in HelpDeskZ affecting version 2.0.2 and earlier. This vulnerability could allow an attacker to send a specially crafted JavaScript payload within the email field and partially take control of an authenticated user's browser session.
0
Attacker Value
Unknown

CVE-2022-31400

Disclosure Date: June 13, 2022 (last updated October 07, 2023)
A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
Attacker Value
Unknown

CVE-2022-31398

Disclosure Date: June 13, 2022 (last updated October 07, 2023)
A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
Attacker Value
Unknown

CVE-2020-26546

Disclosure Date: October 12, 2020 (last updated February 22, 2025)
An issue was discovered in HelpDeskZ 1.0.2. The feature to auto-login a user, via the RememberMe functionality, is prone to SQL injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer