First published: Tue Apr 01 2025(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk allows Path Traversal. This issue affects JS Help Desk: from n/a through 2.9.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
JoomSky JS Help Desk | <=2.9.1 | |
WordPress JS Help Desk | <=2.9.1 |
Update the WordPress JS Help Desk plugin to the latest available version (at least 2.9.2).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30882 is considered a significant security issue as it allows path traversal attacks in JoomSky JS Help Desk.
To resolve CVE-2025-30882, update JoomSky JS Help Desk to version 2.9.2 or later where the vulnerability has been addressed.
CVE-2025-30882 may allow attackers to access sensitive files outside of the intended directories, leading to data exposure.
CVE-2025-30882 affects JoomSky JS Help Desk versions up to and including 2.9.1.
Yes, WordPress JS Help Desk versions up to and including 2.9.1 are also vulnerable to CVE-2025-30882.