CVE-2020-11466 Information
Feb 14, 2021
cve
Description
An issue was discovered in Deskpro before 2019.8.0. The /api/tickets endpoint failed to properly validate a user’s privilege allowing an attacker to retrieve arbitrary information about all helpdesk tickets stored in database with numerous filters. This leaked sensitive information to unauthorized parties. Additionally it leaked ticket authentication code making it possible to make changes to a ticket.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
https://blog.redforce.io/attacking-helpdesks-part-1-rce-chain-on-deskpro/ https://support.deskpro.com/en/news/posts/deskpro-security-update-2019-09 https://support.deskpro.com/en/news/posts/deskpro-v2019-8-0-released-security-update
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.3
Share on: