← Back
CVE-2023-49214
raw json
nvd nist
Published: Nov 23, 2023
Modified: Jun 17, 2026
Bookmark
JSON object
Copy
×
Loading...
CVSS v3
9.8 CRITICAL
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability:
3.9
/
Impact:
5.9
Source: NVD
Description
Usedesk before 1.7.57 allows chat template injection.
Affected (1)
Products:
Usedesk
:
Usedesk
Usedesk
1 product
Subscribe
Cancel
Confirm
Usedesk
Subscribe
Cancel
Confirm
Configuration A
1 vulnerable
Vulnerable Software
Affected Versions
Usedesk
Usedesk
Before 1.7.57
Related CWEs
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
References (2)
https://usedesk.ru/updates_september23
Source: cve@mitre.org
Vendor Advisory
https://usedesk.ru/updates_september23
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.
Load History