CVE-2025-30882: WordPress JS Help Desk plugin <= 2.9.1 - Arbitrary File Download vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-support-ticket allows Path Traversal.This issue affects JS Help Desk: from n/a through <= 2.9.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30882?
CVE-2025-30882 is considered a significant security issue as it allows path traversal attacks in JoomSky JS Help Desk.
How do I fix CVE-2025-30882?
To resolve CVE-2025-30882, update JoomSky JS Help Desk to version 2.9.2 or later where the vulnerability has been addressed.
What impact does CVE-2025-30882 have on affected systems?
CVE-2025-30882 may allow attackers to access sensitive files outside of the intended directories, leading to data exposure.
Which versions of JoomSky JS Help Desk are affected by CVE-2025-30882?
CVE-2025-30882 affects JoomSky JS Help Desk versions up to and including 2.9.1.
Is WordPress JS Help Desk also affected by CVE-2025-30882?
Yes, WordPress JS Help Desk versions up to and including 2.9.1 are also vulnerable to CVE-2025-30882.