Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Deskpro HIGH 7.2
CVE-2021-35391

Server Side Request Forgery vulnerability found in Deskpro Support Desk v2021.21.6 allows attackers to execute arbitrary code via a crafted URL.

No fix yet
Fix from $1,950 2023-07-21
Deskpro MEDIUM 5.4
CVE-2021-36695

Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in the download file …

No fix yet
Fix from $1,600 2021-09-08
Deskpro MEDIUM 5.4
CVE-2021-36696

Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social media links…

No fix yet
Fix from $1,600 2021-09-07
Deskpro MEDIUM 5.4
CVE-2020-28722

Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account …

Fix: after 2020.2.3.48207
Fix from $1,600 2021-05-12
Deskpro HIGH 8.8
CVE-2020-11465

An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to…

Fix: 2019.8.0+
Fix from $1,950 2020-04-01
Deskpro HIGH 7.5
CVE-2020-11463

An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an atta…

Fix: 2019.8.0+
Fix from $1,950 2020-04-01
Deskpro HIGH 7.2
CVE-2020-11467

An issue was discovered in Deskpro before 2019.8.0. This product enables administrators to modify the helpdesk interface by editing /portal/api/style…

Fix: 2019.8.0+
Fix from $1,950 2020-04-01
Deskpro MEDIUM 6.8
CVE-2006-6159

Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in DeskPRO 2.0.0 and 2.0.1 allow remote attackers to inject arbitrary web script…

Mitigation only
Fix from $1,600 2006-11-28
Deskpro MEDIUM 5.0
CVE-2003-0874

Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized activitie…

Patch available
Fix from $1,600 2003-11-17