CVE-2017-14320 describes a critical vulnerability in Mirasvit Helpdesk MX versions prior to 1.5.3, allowing remote attackers to execute arbitrary code due to insufficient filtering of uploaded files. With a CVSS score of 8.0 (HIGH), this flaw can lead to complete compromise of confidentiality, integrity, and availability, requiring low privileges and user interaction over a network. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered community attention and media coverage, including reports of Magento sites being compromised via this helpdesk widget. Despite its age, its high impact potential warrants continued awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.5.2CPE matchmatch criteria | cpe:2.3:a:mirasvit:helpdesk_mx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.