← back
CVE-2023-1125mediumCWE-639

Ruby Help Desk < 1.3.4 - Subscriber+ Ticket Update via IDOR

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.6%
exploitation probability
0.6%top 57% of all CVEs
observed exploitation
nono source reports it
The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected products
Unknown · Ruby Help Desk