Missing Authorization vulnerability Affects JS Help Desk - Best Help Desk & Support Plugin
CVE-2024-31273
9.8CRITICAL
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 9 June 2024
Summary
A missing authorization vulnerability has been identified in the JS Help Desk – Best Help Desk & Support Plugin, which allows for unauthorized access to certain functionalities within the plugin. This issue may lead to exposure of sensitive information and unauthorized actions that could compromise the integrity of help desk operations. Affected versions include any prior to and including 2.8.3. It is crucial for users to evaluate their installations promptly to mitigate the risks associated with this vulnerability.
Affected Version(s)
JS Help Desk – Best Help Desk & Support Plugin <= 2.8.3
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Fariq Fadillah Gusti Insani (Patchstack Alliance)