MEDIUM🇬🇧 English

CVE-2023-1125

CVSS 6.5v3.1pub. 2023-05-02upd. 2025-01-30

The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  • Wpruby Ruby Help Desk

    APP
    Wpruby
    < 1.3.4
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2021-4360CRITICAL9.9PL ✓ten sam vendor

Privilege Escalation w pluginie WordPress Controlled Admin Access

CVE-2021-24215CRITICAL9.8PL ✓ten sam vendor

Brak kontroli dostępu w pluginie WordPress Controlled Admin Access