Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2023-23716

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Zendesk Zendesk Support for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zendesk Support for WordPress: from n/a through 1.8.4.
0
Attacker Value
Unknown

CVE-2024-42363

Disclosure Date: August 20, 2024 (last updated August 21, 2024)
Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController. The role parameter flows into the RoleConfigFile initializer and then into the Kubernetes::Util.parse_file method where it is unsafely deserialized using the YAML.load_stream method. This issue may lead to Remote Code Execution (RCE). This vulnerability is fixed in 3385.
0
Attacker Value
Unknown

CVE-2021-36750

Disclosure Date: December 22, 2021 (last updated October 07, 2023)
ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
Attacker Value
Unknown

CVE-2018-20857

Disclosure Date: July 26, 2019 (last updated November 27, 2024)
Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!---->. and then the attacker's domain name.
0
Attacker Value
Unknown

CVE-2015-6921

Disclosure Date: September 11, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors.
0