Vulnerabilities
Products Security index
Vulnerabilities
CVE-2021-45785
TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that would perform a GET request to the /api/v1/admin/restart endpoint, then the victim (who has sufficient privileges), would visit the page and the server restart would begin. The attacker must know the full URL that TruDesk is on in order to craft the webpage.
CVE-2023-26982
Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.
CVE-2022-2128
Unrestricted Upload of File with Dangerous Type in polonel/trudesk
CVE-2022-2023
Incorrect Use of Privileged APIs in polonel/trudesk
CVE-2022-1947
Use of Incorrect Operator in polonel/trudesk
