Ruby Help Desk < 1.3.4 - Subscriber+ Ticket Update via IDOR
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.6%
exploitation probability
0.6%top 57% of all CVEs
observed exploitation
nono source reports it
The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected products
Unknown · Ruby Help Desk