VYPR

Faveo Helpdesk & Servicedesk

by Ladybird Web Solution

CVEs (3)

  • CVE-2024-46482HigOct 22, 2024
    risk 0.53cvss 8.2epss 0.00

    An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .html or .svg file.

  • CVE-2026-72554MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via the v1 REST API. The API verifies the existence of the requested ticket but not ownership,…

  • CVE-2024-51377MedNov 1, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to execute arbitrary code via the Subject and Identifier fields

VYPR — Vulnerability Intelligence