uvdesk/community-skeleton
Releases26
Frequency2 months 3 weeks
Last Release
Stars19.4K
UVdesk Open Source Community Helpdesk is a comprehensive ticketing support system designed for everyone, offering robust features to streamline customer support and collaboration.
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| = 1.1.1 | 9.8 CRITICAL | — | ||
UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application. | ||||
| = 1.1.1, <= 1.1.1 | 8.8 HIGH | — | ||
Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the application does not properly validate profile pictures uploaded by customers. | ||||
| = 1.1.1, <= 1.1.1 | 6.1 MEDIUM | — | ||
Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible because the application does not correctly validate the message sent by the clients in the ticket. | ||||
| < 1.1.0 | 4.8 MEDIUM | — | ||
Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0. | ||||