The trudesk application allows large characters to insert in the input field "Full Name" on the signup field which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request in GitHub repository polonel/trudesk prior to 1.2.2. This can lead to Denial of service.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HTrudesk Project Trudesk
APPTrudesk Project< 1.2.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
Related vulnerabilities
CVE-2022-2128CRITICAL9.8PL ✓same product
Nieograniczony upload niebezpiecznych plików w Trudesk (RCE)
CVE-2022-2023CRITICAL9.8PL ✓same product
Nieprawidłowe użycie uprzywilejowanych API w Trudesk przed wersją 1.2.4
CVE-2022-1775CRITICAL9.8PL ✓same product
Słabe wymagania dotyczące haseł w Trudesk (brak wymuszania złożoności)
CVE-2022-1808HIGH8.8same product
Execution with Unnecessary Privileges in GitHub repository polonel/trudesk prior to 1.2.3.
CVE-2022-1931HIGH8.1same product
Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3.