This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulnerability, and already fixed the issue in Helpdesk 3.0.1 and later versions.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2020-22293 | This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulnerability, and already fixed the issue in Helpdesk 3.0.1 and later versions. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://www.qnap.com/zh-tw/security-advisory/qsa-20-03 |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-08-04T07:09:54.662Z
Reserved: 2019-12-09T00:00:00
Link: CVE-2020-2500

No data.

Status : Modified
Published: 2020-07-01T16:15:13.073
Modified: 2024-11-21T05:25:21.487
Link: CVE-2020-2500

No data.

No data.