Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-46226

Опубликовано: 26 фев. 2025
Источник: nvd
CVSS3: 4.8
EPSS Низкий

Описание

A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ticket.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:helpdeskz:helpdeskz:*:*:*:*:*:*:*:*
Версия до 2.0.2 (исключая)

EPSS

Процентиль: 20%
0.00066
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
github
12 месяцев назад

A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ticket.

EPSS

Процентиль: 20%
0.00066
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79