### [CVE-2018-19948](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19948) ![](https://img.shields.io/static/v1?label=Product&message=Helpdesk&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3C%203.0.3%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-352%20Cross-Site%20Request%20Forgery%20(CSRF)&color=brighgreen) ### Description The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later. ### POC #### Reference No PoCs from references. #### Github - https://github.com/404notf0und/CVE-Flow