Vulnerabilities > Deskpro

DATE CVE VULNERABILITY TITLE RISK
2023-07-21 CVE-2021-35391 Server-Side Request Forgery (SSRF) vulnerability in Deskpro 2021.21.6
Server Side Request Forgery vulnerability found in Deskpro Support Desk v2021.21.6 allows attackers to execute arbitrary code via a crafted URL.
network
low complexity
deskpro CWE-918
7.2
2021-09-08 CVE-2021-36695 Cross-site Scripting vulnerability in Deskpro 2021.1.6
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile due to lack of input validation.
network
low complexity
deskpro CWE-79
5.4
2021-09-07 CVE-2021-36696 Cross-site Scripting vulnerability in Deskpro 2021.1.6
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social media links on a user profile due to lack of input validation.
network
low complexity
deskpro CWE-79
5.4
2021-05-12 CVE-2020-28722 Cross-site Scripting vulnerability in Deskpro 2020.2.3.48207/20200730
Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.
network
low complexity
deskpro CWE-79
5.4
2020-04-01 CVE-2020-11467 Deserialization of Untrusted Data vulnerability in Deskpro
An issue was discovered in Deskpro before 2019.8.0.
network
low complexity
deskpro CWE-502
7.2
2020-04-01 CVE-2020-11466 Improper Privilege Management vulnerability in Deskpro
An issue was discovered in Deskpro before 2019.8.0.
network
low complexity
deskpro CWE-269
4.3
2020-04-01 CVE-2020-11465 Missing Authorization vulnerability in Deskpro
An issue was discovered in Deskpro before 2019.8.0.
network
low complexity
deskpro CWE-862
8.8
2020-04-01 CVE-2020-11464 Improper Privilege Management vulnerability in Deskpro
An issue was discovered in Deskpro before 2019.8.0.
network
low complexity
deskpro CWE-269
4.3
2020-04-01 CVE-2020-11463 Missing Authorization vulnerability in Deskpro
An issue was discovered in Deskpro before 2019.8.0.
network
low complexity
deskpro CWE-862
7.5