CVE-2017-14146: Helpdezk

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\app\uploads\helpdezk\attachments\ directory.

Affected products

Published 2017-09-05. Last modified 2026-06-17.