cvefeed.io
Path Traversal Vulnerability in Faveo Helpdesk Disclosed
Article Content
A path traversal vulnerability (CVE-2026-78435) has been identified in Faveo Helpdesk versions up to 2.0.3, affecting the unlink function in app/Http/Controllers/Admin/helpdesk/SettingsController.php. This vulnerability allows remote attackers to manipulate the data1 parameter, potentially deleting or modifying files outside the intended directory. The issue was reported to the project on August 24, 2026, but no response has been received from the maintainers. Although a patch was released on August 25, 2026, there is currently no evidence of public proof-of-concept exploits or active exploitation in the wild. Security professionals are advised to upgrade to versions beyond 2.0.3 and implement strict input validation. The CVSS score for this vulnerability is 4.0, indicating a medium severity level. The vulnerability has been disclosed publicly, raising concerns about its potential exploitation.
Key Points: • CVE-2026-78435 affects Faveo Helpdesk versions up to 2.0.3. • The vulnerability allows remote path traversal attacks via the unlink function. • A patch was released on August 25, 2026, following public disclosure.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.