Vulnerabilities > Helpdezk > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-04 CVE-2023-3037 Unspecified vulnerability in Helpdezk 1.1.10
Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10.
network
low complexity
helpdezk
8.6
2023-10-04 CVE-2023-3038 SQL Injection vulnerability in Helpdezk 1.1.10
SQL injection vulnerability in HelpDezk Community affecting version 1.1.10.
network
low complexity
helpdezk CWE-89
7.5
2017-09-05 CVE-2017-14146 Code Injection vulnerability in Helpdezk 1.1.1
HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\app\uploads\helpdezk\attachments\ directory.
network
low complexity
helpdezk CWE-94
8.8
2017-04-05 CVE-2017-7447 Cross-Site Request Forgery (CSRF) vulnerability in Helpdezk 1.1.1
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
network
low complexity
helpdezk CWE-352
8.8
2017-04-05 CVE-2017-7446 Cross-Site Request Forgery (CSRF) vulnerability in Helpdezk 1.1.1
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
network
low complexity
helpdezk CWE-352
8.8