Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-45785

Опубликовано: 24 июн. 2024
Источник: nvd
CVSS3: 6.5
CVSS3: 4.3
EPSS Низкий

Описание

TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that would perform a GET request to the /api/v1/admin/restart endpoint, then the victim (who has sufficient privileges), would visit the page and the server restart would begin. The attacker must know the full URL that TruDesk is on in order to craft the webpage.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:trudesk_project:trudesk:1.1.11:*:*:*:*:*:*:*

EPSS

Процентиль: 21%
0.00069
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-352
CWE-352

Связанные уязвимости

CVSS3: 6.5
github
больше 1 года назад

TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that would perform a GET request to the /api/v1/admin/restart endpoint, then the victim (who has sufficient privileges), would visit the page and the server restart would begin. The attacker must know the full URL that TruDesk is on in order to craft the webpage.

EPSS

Процентиль: 21%
0.00069
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-352
CWE-352