CVE-2015-4071: Helpdesk Pro Project Helpdesk Pro

Medium severity, CVSS 5.3. EPSS: 9.6% chance of exploitation in the next 30 days.

The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/component/helpdeskpro/?view=ticket&id={ticketId}.

Affected products

Published 2017-08-18. Last modified 2026-06-17.