Medium severity5.4NVD Advisory· Published May 12, 2021· Updated Jun 17, 2026
CVE-2020-28722
CVE-2020-28722
Description
Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Deskpro/Cloud Platformdescription
- Range: 2020.2.3.48207
- Range: 2020.2.3.48207
cpe:2.3:a:deskpro:deskpro:*:*:*:*:cloud:*:*:*+ 1 more
- cpe:2.3:a:deskpro:deskpro:*:*:*:*:cloud:*:*:*range: >=2020-07-30,<=2020.2.3.48207
- cpe:2.3:a:deskpro:deskpro:*:*:*:*:on-premise:*:*:*range: >=2020-07-30,<=2020.2.3.48207
Patches
Vulnerability mechanics
References
1- www.r29k.com/articles/bb/stored-xss-in-deskpronvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.