Peppermint-Lab/peppermint

Peppermint-Lab/peppermint

Releases35
Frequency1 month 1 week
Last Release
Stars3.16K
An open source issue management & help desk solution. A zendesk & jira alternative

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
7.2 HIGH

Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges to admin and gain complete access to the system as the authorization mechanism is not validated on the server side and only on the client side. This can result, for example, in creating a new admin user in the system which enables persistent access for the attacker as an administrator.

< 0.2.47.5 HIGH

Peppermint Ticket Management before 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/users/file/download?filepath=./../ POST request.

<= 0.2.45.3 MEDIUM

Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/download?filepath=../ POST request.

<= 0.2.48.8 HIGH

An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie.

= 0.2.48.1 HIGH

An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted request.