CVE-2023-50839
CRITICAL NUCLEIWiselyhub JS Help Desk < 2.8.1 - SQL Injection
Title source: ruleDescription
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.1.
Exploits (2)
nomisec
WRITEUP
by Francesco-CyberIntelligence · poc
https://github.com/Francesco-CyberIntelligence/bug-bounty-findings-o-research-disclosures.
github
WORKING POC
by Sechunt3r · pythonpoc
https://github.com/Sechunt3r/CVE-POCs/tree/main/CVE-2023-50839
Nuclei Templates (1)
JS Help Desk <= 2.8.1 - SQL Injection
CRITICALVERIFIEDby Shivam Kamboj
Scores
CVSS v3
9.3
EPSS
0.1871
EPSS Percentile
95.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Details
CWE
CWE-89
Status
published
Products (1)
wiselyhub/js_help_desk
< 2.8.1
Published
Dec 28, 2023
Tracked Since
Feb 18, 2026