Known Vulnerabilities for products from Uvdesk
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Uvdesk".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-37635 json | UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain ac... | 9.8 - CRITICAL | 2023-10-23 | 2023-10-30 |
| CVE-2023-1197 json | Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0. | 4.8 - MEDIUM | 2023-03-06 | 2023-03-11 |
| CVE-2023-0325 json | Uvdesk version 1.1.1 allows an unauthenticated remote attacker to exploit a stored XSS in the application. This is possible b... | 6.1 - MEDIUM | 2023-04-04 | 2023-04-11 |
| CVE-2023-0265 json | Uvdesk version 1.1.1 allows an authenticated remote attacker to execute commands on the server. This is possible because the ... | 8.8 - HIGH | 2023-04-04 | 2023-04-11 |