PT-2007-5593 · Deskpro · Deskpro
Published
2007-08-18
·
Updated
2018-10-15
·
CVE-2007-4412
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
DeskPRO version 3.0.2
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to various API endpoints, including "techs.php", "ticket category.php", "ticket priority.php", "ticket workflow.php", "ticket escalate.php", "fields ticket.php", "ticket rules web.php", "ticket displayfields.php", "ticket rules mail.php", "fields user.php", "fields faq.php", and "user help.php". The affected endpoints are located in the "admincp/" directory and possibly a directory on the "User side".
Recommendations
For DeskPRO version 3.0.2, consider disabling access to the affected API endpoints until a patch is available. Restrict access to the
admincp/ directory and possibly the directory on the "User side" to minimize the risk of exploitation. Avoid using unspecified parameters in the affected endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Deskpro