CVE-2018-6007

HIGH

JS Support Ticket 1.1.0 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-6007. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary This is a CSRF exploit for Joomla! Component JS Support Ticket 1.1.0, allowing an attacker to inject HTML code or edit tickets via a crafted form submission. The PoC demonstrates how hidden form fields can be manipulated to perform unauthorized actions.

Description

CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · htmlwebappsphp
https://www.exploit-db.com/exploits/43912

This is a CSRF exploit for Joomla! Component JS Support Ticket 1.1.0, allowing an attacker to inject HTML code or edit tickets via a crafted form submission. The PoC demonstrates how hidden form fields can be manipulated to perform unauthorized actions.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Joomla! Component JS Support Ticket 1.1.0
No auth needed
Prerequisites: Victim must be authenticated and tricked into submitting the form
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43912/

Scores

CVSS v3 8.8
EPSS 0.0031
EPSS Percentile 54.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
joomsky/js_support_ticket 1.1.0
Published Jan 29, 2018
Tracked Since Feb 18, 2026