First published: Fri Sep 06 2024(Updated: )
A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following version: Helpdesk 3.3.1 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS Helpdesk | <3.3.1 |
We have already fixed the vulnerability in the following version: Helpdesk 3.3.1 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27125 has been classified as a cross-site scripting (XSS) vulnerability affecting Helpdesk, posing significant risk if exploited.
To fix CVE-2024-27125, upgrade to Helpdesk version 3.3.1 or later.
Authenticated administrators using Helpdesk versions prior to 3.3.1 are affected by CVE-2024-27125.
If exploited, CVE-2024-27125 could allow attackers to inject malicious code into the Helpdesk application.
CVE-2024-27125 affects all versions of Helpdesk prior to version 3.3.1.