Helpy version 2.8.0 allows an unauthenticated remote attacker to exploit an XSS stored in the application. This is possible because the application does not correctly validate the attachments sent by customers in the ticket.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12418 | Helpy version 2.8.0 allows an unauthenticated remote attacker to exploit an XSS stored in the application. This is possible because the application does not correctly validate the attachments sent by customers in the ticket. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-02-13T16:20:19.701Z
Reserved: 2023-01-17T00:00:00.000Z
Link: CVE-2023-0357
Updated: 2024-08-02T05:10:55.505Z
Status : Modified
Published: 2023-04-04T23:15:07.153
Modified: 2025-02-13T17:15:54.763
Link: CVE-2023-0357
No data.
OpenCVE Enrichment
No data.
EUVD