### [CVE-2018-19946](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19946) ![](https://img.shields.io/static/v1?label=Product&message=Helpdesk&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3C%203.0.3%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-295%20Improper%20Certificate%20Validation&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-297%20Improper%20Validation%20of%20Certificate%20with%20Host%20Mismatch&color=brighgreen) ### Description The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already fixed the issue in Helpdesk 3.0.3 and later. ### POC #### Reference No PoCs from references. #### Github - https://github.com/404notf0und/CVE-Flow