Helpdeskadvanced
Vendor:
First CVE: Jan 13, 2025 · Active for 1 year
10
Total CVEs
More Total CVEs than 89% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Helpdeskadvanced over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 13, 2025
18 months ago
Most Recent CVE
Jan 13, 2025
560 days ago
CVE Severity & Scoring
Helpdeskadvanced10 CVEs
40%
60%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (70.0%)
Unknown0 (0.0%)
Required3 (30.0%)
Privileges Required
Low3 (30.0%)
High0 (0.0%)
None7 (70.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-42225HIGH Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function. | Jan 13, 2025 | 7.5 | 23 | NO | NO |
CVE-2023-42231HIGH Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can delete admin users by sending a request to the "WSCView/Delet | Jan 13, 2025 | 8.1 | 22 | NO | NO |
CVE-2023-42228HIGH Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL rules by sending a request to the "AclList | Jan 13, 2025 | 8.8 | 22 | NO | NO |
CVE-2023-42226HIGH Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function. | Jan 13, 2025 | 7.5 | 22 | NO | NO |
CVE-2023-42232HIGH Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function. | Jan 13, 2025 | 7.5 | 21 | NO | NO |
CVE-2023-42227HIGH Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function. | Jan 13, 2025 | 7.5 | 20 | NO | NO |
CVE-2023-42233MEDIUM Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function. | Jan 13, 2025 | 6.1 | 19 | NO | NO |
CVE-2023-42229MEDIUM Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticated SOAP requests to the WSConne | Jan 13, 2025 | 6.5 | 19 | NO | NO |
CVE-2023-42234MEDIUM Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function. | Jan 13, 2025 | 5.4 | 17 | NO | NO |
CVE-2023-42230MEDIUM Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function. | Jan 13, 2025 | 6.1 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Helpdeskadvanced
Top CWEs
Versions
No cataloged versions.