CVE-2023-1724: Ladybirdweb Faveo Helpdesk
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
Faveo Helpdesk Enterprise version 6.0.1 allows an attacker with agent permissions to perform privilege escalation on the application. This occurs because the application is vulnerable to stored XSS.
Affected products
- Ladybirdweb Faveo Helpdesk: up to and including 6.0.1
Published 2023-06-24. Last modified 2026-06-17.