CVE-2024-8632

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'kbs_ajax_load_front_end_replies' and 'kbs_ajax_mark_reply_as_read' functions in all versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to read replies of any ticket, and mark any reply as read.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:logon:kb_support:*:*:*:*:*:wordpress:*:*

History

10 Feb 2025, 16:00

Type Values Removed Values Added
First Time Logon kb Support
Logon
CWE CWE-862
CPE cpe:2.3:a:logon:kb_support:*:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : unknown
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/767b1234-5b4a-4baa-9048-7b2e413cdba5?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/767b1234-5b4a-4baa-9048-7b2e413cdba5?source=cve - Third Party Advisory
References () https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L439 - () https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L439 - Product
References () https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L342 - () https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L342 - Product

01 Oct 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-01 08:15

Updated : 2025-02-10 16:00


NVD link : CVE-2024-8632

Mitre link : CVE-2024-8632


JSON object : View

Products Affected

logon

  • kb_support
CWE

No CWE.