/ WEB EXPLOITATION · CVE-2024-46638 — STORED XSS IN HELPDESKZ V2.0.2
— · — · — v 4.2 · MMXXVI

CVE-2024-46638 — Stored XSS in HelpDeskZ v2.0.2

Stored Cross-Site Scripting in HelpDeskZ v2.0.2 — disclosed and assigned CVE-2024-46638.

Summary

A stored cross-site scripting (XSS) vulnerability was identified in HelpDeskZ v2.0.2, an open-source ticketing / help-desk platform.

Identifiers

  • CVE: CVE-2024-46638
  • Class: Stored Cross-Site Scripting (XSS)
  • Component: HelpDeskZ v2.0.2
  • Reporter: Ashfaqul Haq

References

For the canonical record and any update on affected versions, see the public CVE-2024-46638 entry in the NVD / MITRE CVE database.

This post is a short disclosure announcement. A longer technical writeup with the proof-of-concept payload may be published once the vendor’s remediation timeline allows.