Back cve.threatint.com Faveo Helpdesk Logo SettingsController.php unlink path traversalA vulnerabili... CVE: New / 22h The project was informed of the problem early through an issue report but has not responded yet. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler.
A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
PUBLISHED Reserved 2026-08-24 | Published 2026-08-24 | Updated 2026-08-24 | Assigner VulDB
MEDIUM: 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P LOW: 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R LOW: 3.8 CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R 4.7 AV:N/AC:L/Au:M/C:N/I:P/A:P/E:POC/RL:ND/RC:UR Problem types Path Traversal Product status 2.0.0 affected 2.0.1 affected 2.0.2 affected 2.0.3 affected Timeline 2026-08-24: Advisory disclosed 2026-08-24: VulDB entry created 2026-08-24: VulDB entry last update Credits geochen (VulDB User) reporter VulDB CNA Team coordinator References vuldb.com/vuln/394713 (VDB-394713 | Faveo Helpdesk Logo SettingsController.php unlink path traversal) vdb-entry technical-description vuldb.com/vuln/394713/cti (VDB-394713 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required vuldb.com/cve/CVE-2026-78435 (CVE-2026-78435 | CVE Analysis and Report) third-party-advisory vuldb.com/submit/886395 (Submit #886395 | faveosuite faveo-helpdesk Commit: 6568aa4 External Control of System or Configuration Setting) third-party-advisory github.com/faveosuite/faveo-helpdesk/issues/8343 exploit issue-tracking cve.org (CVE-2026-78435) nvd.nist.gov (CVE-2026-78435) Download JSON
geochen (VulDB User) reporter
VulDB CNA Team coordinator
vuldb.com/vuln/394713 (VDB-394713 | Faveo Helpdesk Logo SettingsController.php unlink path traversal) vdb-entry technical-description
vuldb.com/vuln/394713/cti (VDB-394713 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required
vuldb.com/cve/CVE-2026-78435 (CVE-2026-78435 | CVE Analysis and Report) third-party-advisory
vuldb.com/submit/886395 (Submit #886395 | faveosuite faveo-helpdesk Commit: 6568aa4 External Control of System or Configuration Setting) third-party-advisory
github.com/faveosuite/faveo-helpdesk/issues/8343 exploit issue-tracking
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
