CVE-2018-19948: CSRF
Published Sep 11, 2020
·Updated
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.
Affected Software
1 affected component
QNAP Helpdesk<3.0.3
Event History
Sep 11, 2020
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this Helpdesk vulnerability?
The vulnerability ID of this Helpdesk vulnerability is CVE-2018-19948.
2
What is the severity of CVE-2018-19948?
The severity of CVE-2018-19948 is medium.
3
Which versions of Helpdesk are affected by CVE-2018-19948?
Earlier versions of Helpdesk up to version 3.0.3 are affected by CVE-2018-19948.
4
How can CVE-2018-19948 be exploited?
CVE-2018-19948 can be exploited through a cross-site request forgery (CSRF) vulnerability.
5
Has QNAP fixed CVE-2018-19948?
Yes, QNAP has already fixed CVE-2018-19948 in Helpdesk version 3.0.3.