CVE-2023-50839

CRITICAL NUCLEI

Wiselyhub JS Help Desk < 2.8.1 - SQL Injection

Title source: rule

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.1.

Exploits (2)

nomisec WRITEUP
by Francesco-CyberIntelligence · poc
https://github.com/Francesco-CyberIntelligence/bug-bounty-findings-o-research-disclosures.
github WORKING POC
by Sechunt3r · pythonpoc
https://github.com/Sechunt3r/CVE-POCs/tree/main/CVE-2023-50839

Nuclei Templates (1)

JS Help Desk <= 2.8.1 - SQL Injection
CRITICALVERIFIEDby Shivam Kamboj

Scores

CVSS v3 9.3
EPSS 0.1871
EPSS Percentile 95.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

Details

CWE
CWE-89
Status published
Products (1)
wiselyhub/js_help_desk < 2.8.1
Published Dec 28, 2023
Tracked Since Feb 18, 2026