SupportCandy
cpe:2.3:a:supportcandy:supportcandy:*:*:*:*:wordpress:*:*
- <= 3.3.0
A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the SupportCandy Helpdesk & Customer Support Ticket System plugin for WordPress, affecting all versions through 3.3.0. The vulnerability arises from inadequate validation of user-controlled keys during file uploads, enabling authenticated attackers to access attachments from support tickets that are not theirs. Furthermore, if an admin permits guest access to tickets, this vulnerability could be exploited by unauthenticated attackers.
Exploitation of this vulnerability allows for unauthorized access to ticket attachments, potentially leading to the disclosure of sensitive information.
To reproduce this vulnerability, an authenticated user can upload a file to a support ticket. Due to the lack of proper validation, it is possible to manipulate the request to download attachments from other users' tickets. If the 'create ticket' option is enabled for guests, this can be done without authentication.
Users are advised to update the SupportCandy Helpdesk & Customer Support Ticket System plugin to version 3.3.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.