{"api_version":"1","generated_at":"2026-07-24T21:14:01+00:00","cve":"CVE-2020-11465","urls":{"html":"https://cve.report/CVE-2020-11465","api":"https://cve.report/api/cve/CVE-2020-11465.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-11465","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-11465"},"summary":{"title":"CVE-2020-11465","description":"An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-04-01 21:15:00","updated_at":"2021-07-21 11:39:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://support.deskpro.com/en/news/posts/deskpro-security-update-2019-09","name":"https://support.deskpro.com/en/news/posts/deskpro-security-update-2019-09","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"Deskpro Security Update (2019-09) - News - Deskpro Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blog.redforce.io/attacking-helpdesks-part-1-rce-chain-on-deskpro/","name":"https://blog.redforce.io/attacking-helpdesks-part-1-rce-chain-on-deskpro/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Attacking HelpDesks Part 1: RCE Chain on DeskPro, with Bitdefender as a Case Study – Redforce","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://support.deskpro.com/en/news/posts/deskpro-v2019-8-0-released-security-update","name":"https://support.deskpro.com/en/news/posts/deskpro-v2019-8-0-released-security-update","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"Deskpro v2019.8.0 Released (Security Update) - Release Announcements - Deskpro Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-11465","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-11465","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"11465","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"deskpro","cpe5":"deskpro","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"11465","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"deskpro","cpe5":"deskpro","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-11465","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://blog.redforce.io/attacking-helpdesks-part-1-rce-chain-on-deskpro/","refsource":"MISC","name":"https://blog.redforce.io/attacking-helpdesks-part-1-rce-chain-on-deskpro/"},{"url":"https://support.deskpro.com/en/news/posts/deskpro-v2019-8-0-released-security-update","refsource":"MISC","name":"https://support.deskpro.com/en/news/posts/deskpro-v2019-8-0-released-security-update"},{"url":"https://support.deskpro.com/en/news/posts/deskpro-security-update-2019-09","refsource":"MISC","name":"https://support.deskpro.com/en/news/posts/deskpro-security-update-2019-09"}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:L/S:U/UI:N","version":"3.0"}}},"nvd":{"publishedDate":"2020-04-01 21:15:00","lastModifiedDate":"2021-07-21 11:39:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:deskpro:deskpro:*:*:*:*:*:*:*:*","versionEndExcluding":"2019.8.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"11465","Ordinal":"172013","Title":"CVE-2020-11465","CVE":"CVE-2020-11465","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"11465","Ordinal":"1","NoteData":"An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"11465","Ordinal":"2","NoteData":"2020-04-01","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"11465","Ordinal":"3","NoteData":"2020-04-01","Type":"Other","Title":"Modified"}]}}}