CVE-2020-28722: Deskpro

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.

Affected products

  • Deskpro Deskpro: from 2020-07-30, up to and including 2020.2.3.48207

Published 2021-05-12. Last modified 2026-06-17.