CVE-2026-78435 | Faveo Helpdesk up to 2.0.3 Logo SettingsController.php unlink data1 path traversal (Issue 8343)
A vulnerability labeled as critical has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-78435. The attack can be launched remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More