Help Desk
by Sysaid
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-22798 | Med | 0.44 | 6.8 | 0.01 | May 12, 2022 | Sysaid – Pro Plus Edition, SysAid Help Desk Broken Access Control v20.4.74 b10, v22.1.20 b62, v22.1.30 b49 - An attacker needs to log in as a guest after that the system redirects him to the service portal or EndUserPortal.JSP, then he needs to change the path in the URL to… | ||
| CVE-2022-40325 | Med | 0.40 | 6.1 | 0.00 | Sep 11, 2022 | SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262. | ||
| CVE-2022-40324 | Med | 0.40 | 6.1 | 0.00 | Sep 11, 2022 | SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258. | ||
| CVE-2022-40323 | Med | 0.40 | 6.1 | 0.00 | Sep 11, 2022 | SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241. | ||
| CVE-2022-40322 | Med | 0.40 | 6.1 | 0.00 | Sep 11, 2022 | SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579. | ||
| CVE-2015-2999 | 0.03 | — | 0.02 | Jun 8, 2015 | Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary SQL commands via the (1) groupFilter parameter in an AssetDetails report to /genericreport, customSQL parameter in a (2) TopAdministratorsByAverageTimer report… |
- risk 0.44cvss 6.8epss 0.01
Sysaid – Pro Plus Edition, SysAid Help Desk Broken Access Control v20.4.74 b10, v22.1.20 b62, v22.1.30 b49 - An attacker needs to log in as a guest after that the system redirects him to the service portal or EndUserPortal.JSP, then he needs to change the path in the URL to…
- risk 0.40cvss 6.1epss 0.00
SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262.
- risk 0.40cvss 6.1epss 0.00
SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258.
- risk 0.40cvss 6.1epss 0.00
SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241.
- risk 0.40cvss 6.1epss 0.00
SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579.
- CVE-2015-2999Jun 8, 2015risk 0.03cvss —epss 0.02
Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary SQL commands via the (1) groupFilter parameter in an AssetDetails report to /genericreport, customSQL parameter in a (2) TopAdministratorsByAverageTimer report…