VYPR
Vendor

Helpdezk

Products
2
CVEs
6
Across products
6
Status
Private

Products

2

Recent CVEs

6
  • CVE-2017-14145CriSep 5, 2017
    risk 0.64cvss 9.8epss 0.01

    HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function.

  • CVE-2017-7447HigApr 5, 2017
    risk 0.60cvss 8.8epss 0.03

    HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.

  • CVE-2017-7446HigApr 5, 2017
    risk 0.60cvss 8.8epss 0.03

    HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.

  • CVE-2017-14146HigSep 5, 2017
    risk 0.57cvss 8.8epss 0.01

    HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\app\uploads\helpdezk\attachments\ directory.

  • CVE-2023-3038Oct 4, 2023
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the rows parameter of the jsonGrid route and extract all the information stored in the application.

  • CVE-2023-3037Oct 4, 2023
    risk 0.00cvss epss 0.01

    Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to access the platform without authentication and retrieve personal data via the jsonGrid parameter.