First published: Fri Sep 11 2020(Updated: )
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Helpdesk | <3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Helpdesk vulnerability is CVE-2018-19948.
The severity of CVE-2018-19948 is medium.
Earlier versions of Helpdesk up to version 3.0.3 are affected by CVE-2018-19948.
CVE-2018-19948 can be exploited through a cross-site request forgery (CSRF) vulnerability.
Yes, QNAP has already fixed CVE-2018-19948 in Helpdesk version 3.0.3.