Description
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-11619 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later. |
References
| Link | Providers |
|---|---|
| https://www.qnap.com/zh-tw/security-advisory/qsa-20-05 |
|
History
No history.
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-08-05T11:51:17.945Z
Reserved: 2018-12-07T00:00:00.000Z
Link: CVE-2018-19948
No data.
Status : Modified
Published: 2020-09-11T15:15:10.993
Modified: 2024-11-21T03:58:52.110
Link: CVE-2018-19948
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD