TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that would perform a GET request to the /api/v1/admin/restart endpoint, then the vict...
6.5CVSS
6.7AI Score
0.0005EPSS
Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.
6.5CVSS
6.4AI Score
0.001EPSS
Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.
5.4CVSS
5.2AI Score
0.001EPSS
Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive data exposure, and worse.
5.4CVSS
5.3AI Score
0.001EPSS
The trudesk application allows large characters to insert in the input field "Full Name" on the signup field which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request in GitHub repository polonel/trudesk prior to 1.2.2. This can lead to Denial of service.
7.5CVSS
7.3AI Score
0.003EPSS
Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capable of executing a malicious javascript code in web page
5.4CVSS
5.3AI Score
0.001EPSS
Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.
6.5CVSS
6.4AI Score
0.001EPSS
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.
8CVSS
7.8AI Score
0.001EPSS
6.5CVSS
6.5AI Score
0.001EPSS
8.8CVSS
8.7AI Score
0.001EPSS
9.8CVSS
9.5AI Score
0.002EPSS
Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.
6.9CVSS
6.7AI Score
0.001EPSS
Execution with Unnecessary Privileges in GitHub repository polonel/trudesk prior to 1.2.3.
8.8CVSS
8.8AI Score
0.001EPSS
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3.
5.3CVSS
5.3AI Score
0.001EPSS
4.9CVSS
5.2AI Score
0.001EPSS
8.1CVSS
8.1AI Score
0.001EPSS
6.5CVSS
6.5AI Score
0.001EPSS
Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.
9.8CVSS
9.6AI Score
0.002EPSS
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.
9.8CVSS
9.5AI Score
0.002EPSS
Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.
5.4CVSS
5.3AI Score
0.001EPSS