Vulnerabilities > Helpdezk
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-04 | CVE-2023-3037 | Unspecified vulnerability in Helpdezk 1.1.10 Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. | 8.6 |
2023-10-04 | CVE-2023-3038 | SQL Injection vulnerability in Helpdezk 1.1.10 SQL injection vulnerability in HelpDezk Community affecting version 1.1.10. | 7.5 |
2020-01-03 | CVE-2014-8337 | Unrestricted Upload of File with Dangerous Type vulnerability in Helpdezk Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the folder parameter. | 9.8 |
2017-09-05 | CVE-2017-14146 | Code Injection vulnerability in Helpdezk 1.1.1 HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\app\uploads\helpdezk\attachments\ directory. | 8.8 |
2017-09-05 | CVE-2017-14145 | SQL Injection vulnerability in Helpdezk 1.1.1 HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function. | 9.8 |
2017-04-05 | CVE-2017-7447 | Cross-Site Request Forgery (CSRF) vulnerability in Helpdezk 1.1.1 HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code. | 8.8 |
2017-04-05 | CVE-2017-7446 | Cross-Site Request Forgery (CSRF) vulnerability in Helpdezk 1.1.1 HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges. | 8.8 |