Description
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social media links on a user profile due to lack of input validation.
Related CPE's
a
deskpro
deskpro
2
References
https://www.r29k.com/articles/bb/stored-xss-in-deskpro#anchor2
ExploitThird Party Advisory
https://www.r29k.com/articles/bb/stored-xss-in-deskpro#anchor2
ExploitThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
5.4 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2021-09-07T09:15:07.697Z
4 years agoLast modified
2024-11-21T05:13:55.873Z
1 year ago