VYPR
Vendor

Truedesk

Products
3
CVEs
22
Across products
22
Status
Private

Products

3

Recent CVEs

22
View all 22 CVEs →
  • CVE-2021-45785Jun 24, 2024
    risk 0.00cvss epss 0.00

    TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that would perform a GET request to the /api/v1/admin/restart…

  • CVE-2022-31456Jul 26, 2023
    risk 0.00cvss epss 0.00

    A cross-site scripting (XSS) vulnerability in Truedesk v1.2.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name parameter.

  • CVE-2022-31455Jul 26, 2023
    risk 0.00cvss epss 0.00

    * A cross-site scripting (XSS) vulnerability in Truedesk v1.2.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a user chat box.

  • CVE-2023-26982Mar 29, 2023
    risk 0.00cvss epss 0.02

    Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.

  • CVE-2022-2128Jun 20, 2022
    risk 0.00cvss epss 0.00

    Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.

  • CVE-2022-2023Jun 20, 2022
    risk 0.00cvss epss 0.00

    Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.

  • CVE-2022-1947May 31, 2022
    risk 0.00cvss epss 0.01

    Use of Incorrect Operator in GitHub repository polonel/trudesk prior to 1.2.3.

  • CVE-2022-1808May 31, 2022
    risk 0.00cvss epss 0.01

    Execution with Unnecessary Privileges in GitHub repository polonel/trudesk prior to 1.2.3.

  • CVE-2022-1893May 31, 2022
    risk 0.00cvss epss 0.00

    Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3.

  • CVE-2022-1926May 31, 2022
    risk 0.00cvss epss 0.00

    Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3.

  • CVE-2022-1931May 31, 2022
    risk 0.00cvss epss 0.00

    Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3.

  • CVE-2022-1752May 21, 2022
    risk 0.00cvss epss 0.00

    Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.

  • CVE-2022-1775May 20, 2022
    risk 0.00cvss epss 0.00

    Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.

  • CVE-2022-1803May 20, 2022
    risk 0.00cvss epss 0.00

    Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.

  • CVE-2022-1770May 20, 2022
    risk 0.00cvss epss 0.00

    Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.

  • CVE-2022-1754May 20, 2022
    risk 0.00cvss epss 0.00

    Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.2.

  • CVE-2022-1728May 16, 2022
    risk 0.00cvss epss 0.00

    Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

  • CVE-2022-1718May 16, 2022
    risk 0.00cvss epss 0.01

    The trudesk application allows large characters to insert in the input field "Full Name" on the signup field which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request in GitHub repository polonel/trudesk prior to 1.2.2. This can lead to Denial of…

  • CVE-2022-1719May 16, 2022
    risk 0.00cvss epss 0.00

    Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capable of executing a malicious javascript code in web page

  • CVE-2022-1044May 12, 2022
    risk 0.00cvss epss 0.00

    Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.