vendor:
Help Desk
by:
Patrik Lantz
7.5
CVSS
HIGH
Remote Code Execution (RCE)
CWE
Product Name: Help Desk
Affected Version From: <= 1.3.6
Affected Version To: 1.3.2006
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Ubuntu 18.04-20.04, Apache, PHP 7.2, Magento 2
2021
Wyomind Help Desk 1.3.6 – Remote Code Execution (RCE)
The Wyomind Help Desk extension up to and including version 1.3.6 is vulnerable to stored XSS, directory traversal, and unrestricted upload of a dangerous file type. These vulnerabilities combined could lead to code execution. An XSS payload can be sent via the ticket message from the front-end in the 'Support - My tickets' section. The payload is triggered when an administrator views the ticket in the Magento 2 backend.
Mitigation:
Upgrade to a patched version of Wyomind Help Desk extension or apply the necessary security fixes provided by the vendor. Additionally, it is recommended to sanitize user input and implement proper access controls to prevent the exploitation of vulnerabilities.