← back
CVE-2023-1125

Ruby Help Desk < 1.3.4 - Subscriber+ Ticket Update via IDOR

CVSS 6.5 MEDIUMEPSS 0.6%CWE-639
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
02 May 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected products
Unknown · Ruby Help Desk

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →