CVE-2020-13994: Mods-For-Hesk Mods For Hesk

High severity, CVSS 8.8. EPSS: 7.4% chance of exploitation in the next 30 days.

An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the server via a ticket because of improper access control of uploaded resources. This might be exploitable in conjunction with CVE-2020-13992 by an unauthenticated attacker.

Affected products

  • Mods-For-Hesk Mods For Hesk: from 3.1.0, up to and including 2019.1.0

Published 2020-07-09. Last modified 2026-06-17.