CVE-2021-35391
- EPSS 0.06%
- Veröffentlicht 21.07.2023 20:15:11
- Zuletzt bearbeitet 21.11.2024 06:12:16
Server Side Request Forgery vulnerability found in Deskpro Support Desk v2021.21.6 allows attackers to execute arbitrary code via a crafted URL.
CVE-2021-36695
- EPSS 0.21%
- Veröffentlicht 08.09.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:55
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file feature on a manager profile due to lack of input validation.
CVE-2021-36696
- EPSS 0.21%
- Veröffentlicht 07.09.2021 11:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:55
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social media links on a user profile due to lack of input validation.
CVE-2020-28722
- EPSS 0.19%
- Veröffentlicht 12.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:23:09
Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.
CVE-2020-11463
- EPSS 0.43%
- Veröffentlicht 01.04.2020 21:15:14
- Zuletzt bearbeitet 21.11.2024 04:57:58
An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve cleartext credentials of all helpdesk email accounts, including incoming and outgoin...
CVE-2020-11464
- EPSS 0.33%
- Veröffentlicht 01.04.2020 21:15:14
- Zuletzt bearbeitet 21.11.2024 04:57:58
An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve sensitive information about all users registered on the system. This includes their full nam...
CVE-2020-11465
- EPSS 0.53%
- Veröffentlicht 01.04.2020 21:15:14
- Zuletzt bearbeitet 21.11.2024 04:57:58
An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including appli...
CVE-2020-11466
- EPSS 0.35%
- Veröffentlicht 01.04.2020 21:15:14
- Zuletzt bearbeitet 21.11.2024 04:57:58
An issue was discovered in Deskpro before 2019.8.0. The /api/tickets endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve arbitrary information about all helpdesk tickets stored in database with numerous filters. ...
CVE-2020-11467
- EPSS 3.99%
- Veröffentlicht 01.04.2020 21:15:14
- Zuletzt bearbeitet 21.11.2024 04:57:58
An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface by editing /portal/api/style/edit-theme-set/template-sources theme templates, and uses TWIG as its template engine. While direct ...
CVE-2007-2011
- EPSS 7.1%
- Veröffentlicht 12.04.2007 19:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in login.php in DeskPro 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.