Skip to content

Commit

Permalink
Mirasvit_Helpdesk vulnerable up to version 1.5.14 (#40)
Browse files Browse the repository at this point in the history
* Mirasvit_Helpdesk vulnerable up to version 1.5.14

There was no security announcement, but Mirasvit_Helpdesk has a "possible XSS security issue" up to 1.5.14: https://mirasvit.com/doc/extension_helpdesk/current/changelog

* Add underscore to Mirasvit modules per new procedure
  • Loading branch information
mzeis authored and gwillem committed Jul 25, 2019
1 parent 53ec218 commit 80ad7b6
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion magento1-vulnerable-extensions.csv
Original file line number Diff line number Diff line change
Expand Up @@ -64,7 +64,7 @@ Magmi,0.7.22,/magmi/,http://magmi.org/magmi-security-issue-solved/,http://wiki.m
Magpleasure_Common,0.8.13,/admin/magpleasure/ajaxform/save/,https://www.alterweb.nl/techtalk/magpleasure_common-security-issue,Abandoned
Magpleasure_Filesystem,,,http://www.magpleasure.com/blog/quick-survey-should-we-leave-the-file-system-extension-alive.html,
MD_Quickview,,,https://magento.com/security/vulnerabilities/sql-injection-vulnerability,
_Mirasvit_Helpdesk,1.5.3,,https://mirasvit.com/blog/helpdesk-mx-for-magento-1-security-issue.html,https://mirasvit.com/magento-extensions/helpdesk.html
_Mirasvit_Helpdesk,1.5.14,,https://mirasvit.com/doc/extension_helpdesk/current/changelog,https://mirasvit.com/magento-extensions/helpdesk.html
_Mirasvit_SEO,1.3.16,,https://mirasvit.com/doc/extension_seosuite/current/changelog,https://mirasvit.com/magento-extensions/advanced-seo-suite.html
MW_Affiliate,,mw_aref=,martin@magemojo.com to gwillem@gmail.com,
Netgo_Gwishlist,,/netgocust/Gwishlist/updategwishlist/,https://gwillem.gitlab.io/2018/10/23/magecart-extension-0days/,https://github.com/wesleyalmd/mageGwishlist/
Expand Down

0 comments on commit 80ad7b6

Please sign in to comment.