RSS   Vulnerabilities for 'Helpdeskz'   RSS

2022-06-13
 
CVE-2022-31398

CWE-79
 

 
A cross-site scripting (XSS) vulnerability in /staff/tools/custom-fields of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.

 
 
CVE-2022-31400

CWE-79
 

 
A cross-site scripting (XSS) vulnerability in /staff/setup/email-addresses of Helpdeskz v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email name field.

 


Copyright 2024, cxsecurity.com

 

Back to Top