HelpDeskZ
cpe:2.3:a:helpdeskz:helpdeskz:*:*:*:*:*:*:*
- < 2.0.2
A stored cross-site scripting vulnerability has been identified in HelpDeskZ versions prior to 2.0.2. This vulnerability allows remote attackers to execute arbitrary JavaScript in the administration panel. The issue arises when a malicious payload is included in the file name of an uploaded file while creating a new ticket.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user accessing the administration panel.
To reproduce this vulnerability, log in as a regular user and create a new ticket. Fill in the required fields and attach an image file with a malicious payload embedded in the filename. After submitting the ticket, access it from the administration panel to trigger the execution of the payload.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.