CVE-2020-11466
Summary
| CVE | CVE-2020-11466 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-01 21:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An issue was discovered in Deskpro before 2019.8.0. The /api/tickets endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve arbitrary information about all helpdesk tickets stored in database with numerous filters. This leaked sensitive information to unauthorized parties. Additionally, it leaked ticket authentication code, making it possible to make changes to a ticket. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Deskpro Security Update (2019-09) - News - Deskpro Support | MISC | support.deskpro.com | Release Notes, Vendor Advisory |
| Attacking HelpDesks Part 1: RCE Chain on DeskPro, with Bitdefender as a Case Study – Redforce | MISC | blog.redforce.io | Exploit, Third Party Advisory |
| Deskpro v2019.8.0 Released (Security Update) - Release Announcements - Deskpro Support | MISC | support.deskpro.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.