Security Advisory

CVE-2024-46226

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-02-26 00:00:00
Last updated 2025-02-26 15:49:02
Assigner mitre
State PUBLISHED

Description

A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ticket.