Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-74295
HistorySep 09, 2021 - 12:00 a.m.

Deskpro Cross-Site Scripting Vulnerability

2021-09-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
4

0.001 Low

EPSS

Percentile

24.8%

Deskpro is a suite of help desk software from Deskpro UK. A cross-site scripting vulnerability exists in versions of Deskpro cloud and on-premise Deskpro prior to 2021.1.6. The vulnerability stems from a lack of input validation of social media links in user profiles, which allows an attacker to inject and execute client-side JavaScript code to hijack cookie session tokens.

0.001 Low

EPSS

Percentile

24.8%

Related for CNVD-2021-74295