CVE-2018-19948 is a Cross-Site Request Forgery (CSRF) vulnerability affecting earlier versions of QNAP Helpdesk. This medium-severity flaw, with a CVSS score of 6.5, could allow attackers to trick NAS users into performing unintended actions via a web application. While the vulnerability has a high integrity impact, it requires user interaction and has no known active exploits, public exploit code, or significant community discussion. QNAP addressed this issue in Helpdesk version 3.0.3 and later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.3CPE matchmatch criteria | cpe:2.3:a:qnap:helpdesk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.