Vulnerability Details CVE-2023-0357
Helpy version 2.8.0 allows an unauthenticated remote attacker to exploit an XSS stored in the application. This is possible because the application does not correctly validate the attachments sent by customers in the ticket.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 47.8%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2023-0357
-
cpe:2.3:a:helpy.io:helpy:2.8.0