« Volver al listado

Trudesk Project

Trudesk Project Trudesk: vulnerabilidades y CVE

Trudesk Project Trudesk tiene 20 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE20
Últimos 12 meses0
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-45785Media (6.5)0.25%—24 jun 2024
TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that…
CVE-2023-26982Media (5.4)1.0%—29 mar 2023
Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.
CVE-2022-1719Media (5.4)0.73%—29 sept 2022
Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capable of executing a malicious javascript code in web page
CVE-2022-1718Alta (7.5)1.1%—29 sept 2022
The trudesk application allows large characters to insert in the input field "Full Name" on the signup field which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request in GitHub repository…
CVE-2022-2128Crítica (9.8)2.9%—20 jun 2022
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.
CVE-2022-2023Crítica (9.8)3.2%—20 jun 2022
Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.
CVE-2022-1947Media (6.5)1.2%—31 may 2022
Use of Incorrect Operator in GitHub repository polonel/trudesk prior to 1.2.3.
CVE-2022-1893Media (5.3)0.83%—31 may 2022
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3.
CVE-2022-1808Alta (8.8)3.5%—31 may 2022
Execution with Unnecessary Privileges in GitHub repository polonel/trudesk prior to 1.2.3.
CVE-2022-1926Media (4.9)0.97%—31 may 2022
Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3.
CVE-2022-1931Alta (8.1)2.1%—31 may 2022
Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3.
CVE-2022-1752Alta (8)2.3%—21 may 2022
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.
CVE-2022-1775Crítica (9.8)2.2%—20 may 2022
Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.
CVE-2022-1803Media (6.9)1.6%—20 may 2022
Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.
CVE-2022-1770Alta (8.8)2.5%—20 may 2022
Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.
CVE-2022-1754Media (6.5)1.0%—20 may 2022
Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.2.
CVE-2022-1728Media (6.5)0.97%—16 may 2022
Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to…
CVE-2022-1044Media (6.5)0.88%—12 may 2022
Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.
CVE-2022-1045Media (5.4)1.6%—11 abr 2022
Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.
CVE-2022-1290Media (5.4)1.7%—10 abr 2022
Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts in the user's browser and it can lead to session hijacking, sensitive…