MEDIUM🇵🇱 Wersja polska

CVE-2023-1125

CVSS 6.5v3.1pub. 2023-05-02upd. 2025-01-30

The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  • Wpruby Ruby Help Desk

    APP
    Wpruby
    < 1.3.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-4360CRITICAL9.9PL ✓same vendor

Privilege Escalation w pluginie WordPress Controlled Admin Access

CVE-2021-24215CRITICAL9.8PL ✓same vendor

Brak kontroli dostępu w pluginie WordPress Controlled Admin Access