NA

CVE-2023-26982

Published: 29/03/2023 Updated: 01/04/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Trudesk v1.2.6 exists to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.

Vulnerable Product Search on Vulmon Subscribe to Product

trudesk project trudesk 1.2.6

Github Repositories

Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.

CVE-2023-26982 Vulnerability Explanation: Trudesk v126 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function Attack Vectors: The attacker must create some ticket and then edit tags in the ticket and insert the XSS payload at the Add Tags input, Create Tag in order to exploit the stored XSS The