Vulnerabilities > Trudesk Project

DATE CVE VULNERABILITY TITLE RISK
2024-06-24 CVE-2021-45785 Cross-Site Request Forgery (CSRF) vulnerability in Trudesk Project Trudesk 1.1.11
TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack.
network
low complexity
trudesk-project CWE-352
6.5
2023-03-29 CVE-2023-26982 Cross-site Scripting vulnerability in Trudesk Project Trudesk 1.2.6
Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.
network
low complexity
trudesk-project CWE-79
5.4
2022-09-29 CVE-2022-1718 Unspecified vulnerability in Trudesk Project Trudesk
The trudesk application allows large characters to insert in the input field "Full Name" on the signup field which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request in GitHub repository polonel/trudesk prior to 1.2.2.
network
low complexity
trudesk-project
7.5
2022-09-29 CVE-2022-1719 Unspecified vulnerability in Trudesk Project Trudesk
Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2.
network
low complexity
trudesk-project
5.4
2022-06-20 CVE-2022-2128 Unspecified vulnerability in Trudesk Project Trudesk
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.
network
low complexity
trudesk-project
critical
9.8
2022-06-20 CVE-2022-2023 Improper Privilege Management vulnerability in Trudesk Project Trudesk
Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.
network
low complexity
trudesk-project CWE-269
critical
9.8
2022-05-31 CVE-2022-1947 Unspecified vulnerability in Trudesk Project Trudesk
Use of Incorrect Operator in GitHub repository polonel/trudesk prior to 1.2.3.
network
low complexity
trudesk-project
6.5
2022-05-31 CVE-2022-1808 Unspecified vulnerability in Trudesk Project Trudesk
Execution with Unnecessary Privileges in GitHub repository polonel/trudesk prior to 1.2.3.
network
low complexity
trudesk-project
8.8
2022-05-31 CVE-2022-1893 Unspecified vulnerability in Trudesk Project Trudesk
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3.
network
low complexity
trudesk-project
5.3
2022-05-31 CVE-2022-1926 Integer Overflow or Wraparound vulnerability in Trudesk Project Trudesk
Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3.
network
low complexity
trudesk-project CWE-190
4.9