What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in JS Help Desk plugin <= 2.7.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in JS Help Desk plugin <= 2.7.1 versions.
Explanation of Vulnerability in Simple Terms
JS Help Desk versions up to 2.7.1 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in administrator, performs unwanted actions on the help desk system without their knowledge. The attack requires the victim to visit the attacker's page while authenticated. This can result in unauthorized modifications or service disruption.
What an attacker can do
Trick a logged-in admin into performing unwanted actions on the help desk system via a malicious webpage.
Potential impact on your site
An attacker can modify help desk settings, create/delete tickets, or disrupt service if an admin visits a malicious link.
Conditions required to exploit
Victim must be logged into JS Help Desk and visit an attacker-controlled webpage.
Key dates
External resources
Related vulnerabilities