Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2023-23716
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in Zendesk Zendesk Support for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zendesk Support for WordPress: from n/a through 1.8.4.
0
Attacker Value
Unknown
CVE-2024-42363
Disclosure Date: August 20, 2024 (last updated August 21, 2024)
Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController. The role parameter flows into the RoleConfigFile initializer and then into the Kubernetes::Util.parse_file method where it is unsafely deserialized using the YAML.load_stream method. This issue may lead to Remote Code Execution (RCE). This vulnerability is fixed in 3385.
0
Attacker Value
Unknown
CVE-2021-36750
Disclosure Date: December 22, 2021 (last updated October 07, 2023)
ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).
0
Attacker Value
Unknown
CVE-2018-20857
Disclosure Date: July 26, 2019 (last updated November 27, 2024)
Zendesk Samlr before 2.6.2 allows an XML nodes comment attack such as a name_id node with user@example.com followed by <!---->. and then the attacker's domain name.
0
Attacker Value
Unknown
CVE-2015-6921
Disclosure Date: September 11, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors.
0