Missing Authorization vulnerability Affects JS Help Desk - Best Help Desk & Support Plugin
CVE-2024-31273

5.3MEDIUM

What is CVE-2024-31273?

A missing authorization vulnerability has been identified in the JS Help Desk – Best Help Desk & Support Plugin, which allows for unauthorized access to certain functionalities within the plugin. This issue may lead to exposure of sensitive information and unauthorized actions that could compromise the integrity of help desk operations. Affected versions include any prior to and including 2.8.3. It is crucial for users to evaluate their installations promptly to mitigate the risks associated with this vulnerability.

Affected Version(s)

JS Help Desk – Best Help Desk & Support Plugin <= 2.8.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fariq Fadillah Gusti Insani (Patchstack Alliance)
.