vendor:
HelpDeskZ
by:
Md. Sadikul Islam
6.1
CVSS
HIGH
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: HelpDeskZ
Affected Version From: 2.0.2
Affected Version To: 2.0.2
Patch Exists: NO
Related CWE:
CPE: a:helpdesk-z:helpdeskz:2.0.2
Platforms Tested: Kali Linux, Firefox 115.1.0esr (64-bit)
2024
Stored XSS Vulnerability via File Name
The vulnerability allows attackers to execute malicious scripts by embedding them in the filename of an image file uploaded as part of creating a new ticket in the HelpDeskZ software version 2.0.2. Successful exploitation can lead to compromise of the administration panel and execution of unauthorized scripts in the administrator's environment.
Mitigation:
To mitigate this vulnerability, input validation should be implemented to sanitize filenames of uploaded files to prevent script execution. Regular security audits and patch updates are recommended.