What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Cross Site Request Forgery.This issue affects CodeBard Help Desk: from n/a through <= 1.1.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Cross Site Request Forgery.This issue affects CodeBard Help Desk: from n/a through <= 1.1.1.
Explanation of Vulnerability in Simple Terms
CodeBard Help Desk versions 1.1.1 and earlier are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the help desk system without the admin's knowledge or consent. This could result in unauthorized changes to help desk settings or data.
What an attacker can do
Trick a logged-in admin into performing unwanted actions on the help desk system via a malicious webpage.
Potential impact on your site
An attacker can modify help desk settings or data if they trick your admin into visiting a malicious link while logged in.
Conditions required to exploit
The victim must be logged into CodeBard Help Desk and visit an attacker-controlled webpage.
Key dates
External resources
Related vulnerabilities