{"api_version":"1","generated_at":"2026-07-23T08:29:31+00:00","cve":"CVE-2018-19947","urls":{"html":"https://cve.report/CVE-2018-19947","api":"https://cve.report/api/cve/CVE-2018-19947.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-19947","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-19947"},"summary":{"title":"CVE-2018-19947","description":"The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.","state":"PUBLIC","assigner":"security@qnap.com","published_at":"2020-09-11 15:15:00","updated_at":"2020-09-16 19:23:00"},"problem_types":["CWE-209"],"metrics":[],"references":[{"url":"https://www.qnap.com/zh-tw/security-advisory/qsa-20-05","name":"https://www.qnap.com/zh-tw/security-advisory/qsa-20-05","refsource":"MISC","tags":["Vendor Advisory"],"title":"Multiple Vulnerabilities in Helpdesk - Security Advisory | QNAP","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-19947","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-19947","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Independent Security Evaluators","lang":""}],"nvd_cpes":[{"cve_year":"2018","cve_id":"19947","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"qnap","cpe5":"helpdesk","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"19947","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"qnap","cpe5":"helpdesk","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@qnap.com","ID":"CVE-2018-19947","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Helpdesk","version":{"version_data":[{"version_affected":"<","version_value":"3.0.3"}]}}]},"vendor_name":"QNAP Systems Inc."}]}},"credit":[{"lang":"eng","value":"Independent Security Evaluators"}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-200 Information Exposure"}]},{"description":[{"lang":"eng","value":"CWE-209 Information Exposure Through an Error Message"}]},{"description":[{"lang":"eng","value":"CWE-210 Information Exposure Through Self-generated Error Message"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://www.qnap.com/zh-tw/security-advisory/qsa-20-05","name":"https://www.qnap.com/zh-tw/security-advisory/qsa-20-05"}]},"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2020-09-11 15:15:00","lastModifiedDate":"2020-09-16 19:23:00","problem_types":["CWE-209"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:qnap:helpdesk:*:*:*:*:*:*:*:*","versionEndExcluding":"3.0.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"19947","Ordinal":"138795","Title":"CVE-2018-19947","CVE":"CVE-2018-19947","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"19947","Ordinal":"1","NoteData":"The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"19947","Ordinal":"2","NoteData":"2020-09-11","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"19947","Ordinal":"3","NoteData":"2020-09-11","Type":"Other","Title":"Modified"}]}}}