PT-2022-13779 · Trudesk · Trudesk

Published

2022-04-10

·

Updated

2023-03-07

·

CVE-2022-1290

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions trudesk versions prior to 1.2.0
Description The issue allows attackers to execute malicious scripts in the user's browser, potentially leading to session hijacking, sensitive data exposure, and other consequences. This is achieved through stored XSS in the Name, Group Name, and Title fields.
Recommendations For versions prior to 1.2.0, update to version 1.2.0 or later to resolve the issue. As a temporary workaround, consider restricting user input in the Name, Group Name, and Title fields to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-1290

Affected Products

Trudesk