CVE-2024-46226

Publication date

2025-02-26 00:00:00

Family

mitre

State

PUBLISHED

Description

A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ticket.