The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'kbs_ajax_load_front_end_replies' and 'kbs_ajax_mark_reply_as_read' functions in all versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to read replies of any ticket, and mark any reply as read.
References
Configurations
History
10 Feb 2025, 16:00
Type | Values Removed | Values Added |
---|---|---|
Summary | (es) El complemento KB Support – WordPress Help Desk y Knowledge Base para WordPress es vulnerable al acceso no autorizado y a la modificación de datos debido a una falta de comprobación de capacidad en las funciones 'kbs_ajax_load_front_end_replies' y 'kbs_ajax_mark_reply_as_read' en todas las versiones hasta la 1.6.6 incluida. Esto permite que atacantes no autenticados lean las respuestas de cualquier ticket y marquen cualquier respuesta como leída. | |
First Time |
Logon kb Support
Logon |
|
References | () https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L342 - Product | |
References | () https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L439 - Product | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/767b1234-5b4a-4baa-9048-7b2e413cdba5?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:logon:kb_support:*:*:*:*:*:wordpress:*:* |
04 Oct 2024, 13:51
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
01 Oct 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-01 08:15
Updated : 2025-02-10 16:00
NVD link : CVE-2024-8632
Mitre link : CVE-2024-8632
CVE.ORG link : CVE-2024-8632
JSON object : View
Products Affected
logon
- kb_support
CWE
CWE-862
Missing Authorization