Filtered by vendor Helpdezk
Subscribe
Total
7 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-7447 | 1 Helpdezk | 1 Helpdezk | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code. | |||||
CVE-2017-7446 | 1 Helpdezk | 1 Helpdezk | 2024-11-21 | 6.8 MEDIUM | 8.8 HIGH |
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges. | |||||
CVE-2017-14146 | 1 Helpdezk | 1 Helpdezk | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\app\uploads\helpdezk\attachments\ directory. | |||||
CVE-2017-14145 | 1 Helpdezk | 1 Helpdezk | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function. | |||||
CVE-2014-8337 | 1 Helpdezk | 1 Helpdezk | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the folder parameter. | |||||
CVE-2023-3038 | 1 Helpdezk | 1 Helpdezk | 2024-02-28 | N/A | 7.5 HIGH |
SQL injection vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the rows parameter of the jsonGrid route and extract all the information stored in the application. | |||||
CVE-2023-3037 | 1 Helpdezk | 1 Helpdezk | 2024-02-28 | N/A | 8.6 HIGH |
Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to access the platform without authentication and retrieve personal data via the jsonGrid parameter. |