CVE-2024-46226
26.02.2025, 16:15
A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ticket.
Vendor | Product | Version |
---|---|---|
helpdeskz | helpdeskz | 𝑥 < 2.0.2 |
𝑥
= Vulnerable software versions