VendorsTrudesk Projecttrudeskall versions
Vulnerabilities

Trudesk Project Trudesk

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2022-2023
Incorrect Use of Privileged APIs in polonel/trudesk
Published 2022-06-20 · Modified
10.0EPSS 0.032
CVE-2022-1770
Improper Privilege Management in polonel/trudesk
Published 2022-05-20 · Modified
9.9EPSS 0.025
CVE-2022-2128
Unrestricted Upload of File with Dangerous Type in polonel/trudesk
Published 2022-06-20 · Modified
9.8EPSS 0.029
CVE-2022-1775
Weak Password Requirements in polonel/trudesk
Published 2022-05-20 · Modified
9.8EPSS 0.022
CVE-2022-1931
Incorrect Synchronization in polonel/trudesk
Published 2022-05-31 · Modified
9.1EPSS 0.021
CVE-2022-1947
Use of Incorrect Operator in polonel/trudesk
Published 2022-05-31 · Modified
9.1EPSS 0.012
CVE-2022-1752
Unrestricted Upload of File with Dangerous Type in polonel/trudesk
Published 2022-05-21 · Modified
9.0EPSS 0.023
CVE-2022-1290
Stored XSS in "Name", "Group Name" & "Title" in polonel/trudesk
Published 2022-04-10 · Modified
9.0EPSS 0.017
CVE-2022-1045
Stored XSS viva .svg file upload in polonel/trudesk
Published 2022-04-11 · Modified
9.0EPSS 0.016
CVE-2022-1808
Execution with Unnecessary Privileges in polonel/trudesk
Published 2022-05-31 · Modified
8.8EPSS 0.035
CVE-2022-1803
Improper Restriction of Rendered UI Layers or Frames in polonel/trudesk
Published 2022-05-20 · Modified
8.4EPSS 0.016
CVE-2022-1754
Integer Overflow or Wraparound in polonel/trudesk
Published 2022-05-20 · Modified
8.4EPSS 0.010
CVE-2022-1044
Sensitive Data Exposure Due To Insecure Storage Of Profile Image in polonel/trudesk
Published 2022-05-12 · Modified
8.2EPSS 0.009
CVE-2022-1926
Integer Overflow or Wraparound in polonel/trudesk
Published 2022-05-31 · Modified
7.6EPSS 0.010
CVE-2022-1728
Allowing long password leads to denial of service in polonel/trudesk in polonel/trudesk
Published 2022-05-16 · Modified
7.6EPSS 0.010
CVE-2022-1718
The trudesk application allows large characters to insert in the input field "Full Name" on the signup field which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request in polonel/trudesk
Published 2022-05-16 · Modified
7.5EPSS 0.010
CVE-2021-45785
TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that would perform a GET request to the /api/v1/admin/restart endpoint, then the victim (who has sufficient privileges), would visit the page and the server restart would begin. The attacker must know the full URL that TruDesk is on in order to craft the webpage.
Published 2024-06-24 · Modified
6.5EPSS 0.003
CVE-2022-1719
Reflected XSS on ticket filter function in polonel/trudesk
Published 2022-05-16 · Modified
5.5EPSS 0.007
CVE-2023-26982
Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.
Published 2023-03-29 · Modified
5.4EPSS 0.010
CVE-2022-1893
Improper Removal of Sensitive Information Before Storage or Transfer in polonel/trudesk
Published 2022-05-31 · Modified
5.3EPSS 0.008