CVE-2023-1125 | Ruby Help Desk < 1.3.4 - Subscriber+ Ticket Update via IDOR
Exp
The Ruby Help Desk WordPress plugin before 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an attacker to close and/or add files and replies to tickets other than their own.
Conclusion & alert: CVE-2023-1125 is rated Exploit Available (56/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.56%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2023-1125
Exploit prediction scoring system (EPSS) score for CVE-2023-1125
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).