Helpy 2.8.0 - Stored Cross-Site Scripting
7,1
High
Discovered by

Offensive Team, Fluid Attacks
Summary
Full name
Helpy 2.8.0 - Stored Cross-Site Scripting
Code name
State
Public
Release date
10 abr 2023
Affected product
Helpy
Affected version(s)
2.8.0
Vulnerability name
Stored cross-site scripting (XSS)
Vulnerability type
Remotely exploitable
Yes
CVSS v3.1 vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
CVSS v3.1 base score
7.1
Exploit available
No
CVE ID(s)
Description
Helpy version 2.8.0 allows an unauthenticated remote attacker to exploit an XSS stored in the application. This is possible because the application does not correctly validate the attachments sent by customers in the ticket.
Vulnerability
This vulnerability occurs because the application does not correctly validate the attachments sent by customers in the ticket.
Exploit
To exploit this vulnerability, simply submit the following malicious HTML code as an attachment to the ticket.
Evidence of exploitation

Our security policy
We have reserved the ID CVE-2023-0357 to refer to this issue from now on. Disclosure policy
System Information
Version: Helpy 2.8.0
Operating System: GNU/Linux
Mitigation
There is currently no patch available for this vulnerability.
References
Vendor page https://github.com/helpyio/helpy/
Timeline
IA generativa
17 ene 2023
Vendor contacted
17 ene 2023
Public disclosure
10 abr 2023