CVE-2021-45785

Source
https://cve.org/CVERecord?id=CVE-2021-45785
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-45785.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-45785
Published
2024-06-24T19:15:11Z
Modified
2026-07-09T05:45:44Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the server, causing a DoS attack. The attacker must craft a webpage that would perform a GET request to the /api/v1/admin/restart endpoint, then the victim (who has sufficient privileges), would visit the page and the server restart would begin. The attacker must know the full URL that TruDesk is on in order to craft the webpage.

References

Affected packages

Git / github.com/polonel/trudesk

Affected ranges

Type
GIT
Repo
https://github.com/polonel/trudesk
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:trudesk_project:trudesk:1.1.11:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.1.11"
        },
        {
            "last_affected": "1.1.11"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

1.*
1.1.11
v1.*
v1.1.11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-45785.json"