CVE-2020-11463
Summary
| CVE | CVE-2020-11463 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-01 21:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An issue was discovered in Deskpro before 2019.8.0. The /api/email_accounts endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve cleartext credentials of all helpdesk email accounts, including incoming and outgoing email credentials. This enables an attacker to get full access to all emails sent or received by the system including password reset emails, making it possible to reset any user's password. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Deskpro Security Update (2019-09) - News - Deskpro Support | MISC | support.deskpro.com | Release Notes, Vendor Advisory |
| Attacking HelpDesks Part 1: RCE Chain on DeskPro, with Bitdefender as a Case Study – Redforce | MISC | blog.redforce.io | Exploit, Third Party Advisory |
| Deskpro v2019.8.0 Released (Security Update) - Release Announcements - Deskpro Support | MISC | support.deskpro.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.