Re Desk maintains a narrowly scoped product line centered on its core Re offering, which occupies a modest footprint in the vulnerability landscape. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Re Desk over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15487CRITICAL Re:Desk 2.3 contains a blind unauthenticated SQL injection vulnerability in the getBaseCriteria() function in the protected/models/Ticket.php file. By modifying the folder GET para | Sep 30, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-15849HIGH Re:Desk 2.3 has a blind authenticated SQL injection vulnerability in the SettingsController class, in the actionEmailTemplates() method. A malicious actor with access to an adminis | Sep 30, 2020 | 7.2 | 19 | NO | NO |
CVE-2020-15488HIGH Re:Desk 2.3 allows insecure file upload. | Sep 30, 2020 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Re Desk.
Media articles that mention a CVE ID that affects a product developed by Re Desk — matched by CVE ID, not by vendor name.