Faveo Helpdesk Enterprise version 6.0.1 allows an attacker with agent permissions to perform privilege escalation on the application. This occurs because the application is vulnerable to stored XSS.
References
Link | Resource |
---|---|
https://fluidattacks.com/advisories/towers/ | Exploit Third Party Advisory |
https://github.com/ladybirdweb/faveo-helpdesk/ | Product |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Fluid Attacks
Published: 2023-06-24T00:13:34.926Z
Updated: 2023-06-24T00:13:34.926Z
Reserved: 2023-03-30T10:59:15.825Z
Link: CVE-2023-1724
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-06-24T01:15:08.543
Modified: 2023-06-30T07:31:30.543
Link: CVE-2023-1724
JSON object: View
Redhat Information
No data.
CWE