Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m535-fq8f-38fp

Опубликовано: 02 мая 2023
Источник: github
Github: Не прошло ревью

Описание

The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.

The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.

EPSS

Процентиль: 26%
0.00091
Низкий

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
nvd
почти 3 года назад

The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.

EPSS

Процентиль: 26%
0.00091
Низкий

Дефекты

CWE-639