CVE Feed

    Dashboard / CVE / CVE-2021-45785

    CVE-2021-45785

    TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that would perform a GET request to the /api/v1/admin/restart endpoint, then the victim (who has sufficient privileges), would visit the page and the server restart would begin. The attacker must know the full URL that TruDesk is on in order to craft the webpage.

    Published:Jun 24, 2024
    Last Modified:Nov 21, 2024
    EPS:Jun 24, 2024
    EPSS Score:0.00069
    CVSS Score:6.5

    Affected Products

    Vendor
    Trudesk Project
    Product
    Trudesk

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High