ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-3037
+1 in the same advisory: …3038
Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10.

Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to access the platform without authentication and retrieve personal data via the jsonGrid parameter.

NVD description · AI analysis pending
8.6
group max
<1%
  • helpdezk helpdezk
CVE-2017-14145
+1 in the same advisory: …14146
HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWar

HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • helpdezk helpdezk
CVE-2017-7447
+1 in the same advisory: …7446
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.

HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.

NVD description · AI analysis pending
8.83% PoC
  • helpdezk helpdezk