Trudesk Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 20
    Known Exploited: 0
    3
    Critical Level Threats
    5
    High Level Threats
    12
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-45785

    TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that would perform a GET request to the /api/v1/admin/restart endpoint, then the victim (who has sufficient privileges), would visit the page and the server restart would begin. The attacker must know the full URL that TruDesk is on in order to craft the webpage.

    Last Modified: Nov 21, 2024
    Published: Jun 24, 2024

    CVE-2023-26982

    Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.

    Last Modified: Feb 18, 2025
    Published: Mar 29, 2023

    CVE-2022-2128

    Unrestricted Upload of File with Dangerous Type in polonel/trudesk

    Last Modified: Nov 21, 2024
    Published: Jun 20, 2022

    CVE-2022-2023

    Incorrect Use of Privileged APIs in polonel/trudesk

    Last Modified: Nov 21, 2024
    Published: Jun 20, 2022

    CVE-2022-1947

    Use of Incorrect Operator in polonel/trudesk

    Last Modified: Nov 21, 2024
    Published: May 31, 2022
    Items Per Page