CVE-2020-21990
Summary
| CVE | CVE-2020-21990 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-29 14:15:00 UTC |
| Updated | 2021-05-08 04:57:00 UTC |
| Description | Emmanuel MyDomoAtHome (MDAH) REST API REST API Domoticz ISS Gateway 0.2.40 is affected by an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this, via a specially crafted request to gain access to sensitive information. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Domoticz | Mydomoathome | 0.240 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zero Science Lab » MyDomoAtHome (MDAH) REST API Domoticz ISS Gateway 0.2.40 Information Disclosure | MISC | www.zeroscience.mk | |
| MyDomoAtHome REST API Domoticz ISS Gateway 0.2.40 - Information Disclosure - Hardware webapps Exploit | EXPLOIT-DB | www.exploit-db.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.