Helpdezk
by Helpdezk
CVEs (4)
| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-14145 | Cri | 0.64 | 9.8 | 0.00 | Sep 5, 2017 | HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function. | |
| CVE-2017-7447 | Hig | 0.60 | 8.8 | 0.00 | Apr 5, 2017 | HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code. | |
| CVE-2017-7446 | Hig | 0.60 | 8.8 | 0.00 | Apr 5, 2017 | HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges. | |
| CVE-2017-14146 | Hig | 0.57 | 8.8 | 0.01 | Sep 5, 2017 | HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\app\uploads\helpdezk\attachments\ directory. |