CVE-2024-2078: Helpdeskz

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A Cross-Site Scripting (XSS) vulnerability has been found in HelpDeskZ affecting version 2.0.2 and earlier. This vulnerability could allow an attacker to send a specially crafted JavaScript payload within the email field and partially take control of an authenticated user's browser session.

Affected products

  • Helpdeskz Helpdeskz: up to and including 2.0.2

Published 2024-03-01. Last modified 2026-06-17.