CVE-2020-13992: Mods-For-Hesk Mods For Hesk

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A Stored XSS issue allows remote unauthenticated attackers to abuse a helpdesk user's logged in session. A user with sufficient privileges to change their login-page image must open a crafted ticket.

Affected products

  • Mods-For-Hesk Mods For Hesk: from 3.1.0, up to and including 2019.1.0

Published 2020-07-09. Last modified 2026-06-17.