VYPR

Qts Helpdesk

by Qnap

CVEs (2)

  • CVE-2018-0714CriAug 13, 2018
    risk 0.64cvss 9.8epss 0.02

    Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run arbitrary commands in the compromised application.

  • CVE-2017-13068HigOct 6, 2017
    risk 0.52cvss 7.5epss 0.03

    QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack.