WyomindCVEs & Vulnerabilities
3 CVEs affecting Wyomind products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
3 CVEs→ All vendors
Most Affected Products
help desk 3
CVE-2021-33353CRITICAL
Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting.
9 Mar 2023
9.8
CVSS
CVE-2021-33352CRITICAL
An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field.
9 Mar 2023
9.8
CVSS
CVE-2021-33351CRITICAL
Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field.
9 Mar 2023
9.0
CVSS
← PrevPage 1 / 1Next →