Vulnerabilities
Vulnerable Software
Helpdezk:  >> Helpdezk  >> 1.1.1  Security Vulnerabilities
HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function.
CVSS Score
9.8
EPSS Score
0.003
Published
2017-09-05
HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\app\uploads\helpdezk\attachments\ directory.
CVSS Score
8.8
EPSS Score
0.007
Published
2017-09-05
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
CVSS Score
8.8
EPSS Score
0.003
Published
2017-04-05
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
CVSS Score
8.8
EPSS Score
0.003
Published
2017-04-05


Contact Us

Shodan ® - All rights reserved