CVE-2023-42230
- EPSS 0.06%
- Veröffentlicht 13.01.2025 22:15:11
- Zuletzt bearbeitet 17.04.2025 17:44:01
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.
CVE-2023-42231
- EPSS 0.1%
- Veröffentlicht 13.01.2025 22:15:11
- Zuletzt bearbeitet 17.04.2025 17:44:04
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can delete admin users by sending a request to the "WSCView/Delete" function.
CVE-2023-42232
- EPSS 0.41%
- Veröffentlicht 13.01.2025 22:15:11
- Zuletzt bearbeitet 17.04.2025 17:44:08
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.
CVE-2023-42233
- EPSS 0.06%
- Veröffentlicht 13.01.2025 22:15:11
- Zuletzt bearbeitet 17.04.2025 17:44:11
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function.
CVE-2023-42234
- EPSS 0.03%
- Veröffentlicht 13.01.2025 22:15:11
- Zuletzt bearbeitet 17.04.2025 17:44:15
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function.
CVE-2023-42225
- EPSS 0.41%
- Veröffentlicht 13.01.2025 22:15:10
- Zuletzt bearbeitet 17.04.2025 17:43:15
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function.
CVE-2023-42226
- EPSS 0.41%
- Veröffentlicht 13.01.2025 22:15:10
- Zuletzt bearbeitet 17.04.2025 17:43:43
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function.
CVE-2023-42227
- EPSS 0.41%
- Veröffentlicht 13.01.2025 22:15:10
- Zuletzt bearbeitet 17.04.2025 17:43:48
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function.
CVE-2023-42228
- EPSS 0.12%
- Veröffentlicht 13.01.2025 22:15:10
- Zuletzt bearbeitet 17.04.2025 17:43:54
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by sending a request to the "AclList/SaveAclRules" administrative function.
CVE-2023-42229
- EPSS 0.67%
- Veröffentlicht 13.01.2025 22:15:10
- Zuletzt bearbeitet 17.04.2025 17:43:58
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticated SOAP requests to the WSConnector service.