TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the…
Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket functio…
The trudesk application allows large characters to insert in the input field "Full Name" on the signup field which can allow attackers to cause a Den…
Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capable of executing a malicious j…
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.
Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.
Use of Incorrect Operator in GitHub repository polonel/trudesk prior to 1.2.3.
Execution with Unnecessary Privileges in GitHub repository polonel/trudesk prior to 1.2.3.
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3.
Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3.
Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.
Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.
Improper Restriction of Rendered UI Layers or Frames in GitHub repository polonel/trudesk prior to 1.2.2.
Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.
Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.2.
Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be a…
Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.
Stored XSS viva .svg file upload in GitHub repository polonel/trudesk prior to v1.2.0.
Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers to execute malicious scripts…