Vulnerabilities > Helpdeskz

DATE CVE VULNERABILITY TITLE RISK
2022-06-13 CVE-2022-31398 Cross-site Scripting vulnerability in Helpdeskz 2.0.2
A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
network
low complexity
helpdeskz CWE-79
4.8
2022-06-13 CVE-2022-31400 Cross-site Scripting vulnerability in Helpdeskz 2.0.2
A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.
network
low complexity
helpdeskz CWE-79
4.8