A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ticket.
CVE ID: CVE-2024-46226
Vendor: n/a
Product: n/a
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 7.53% (scored less or equal to compared to others)
EPSS Date: 2025-03-27 (when was this score calculated)
SSVC Exploitation: poc
SSVC Technical Impact: partial
SSVC Automatable: false