Vulnerability Description
An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve sensitive information about all users registered on the system. This includes their full name, privilege, email address, phone number, etc.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Deskpro | Deskpro | < 2019.8.0 |
Related Weaknesses (CWE)
References
- https://blog.redforce.io/attacking-helpdesks-part-1-rce-chain-on-deskpro/ExploitThird Party Advisory
- https://support.deskpro.com/en/news/posts/deskpro-security-update-2019-09Release NotesVendor Advisory
- https://support.deskpro.com/en/news/posts/deskpro-v2019-8-0-released-security-upRelease NotesVendor Advisory
- https://blog.redforce.io/attacking-helpdesks-part-1-rce-chain-on-deskpro/ExploitThird Party Advisory
- https://support.deskpro.com/en/news/posts/deskpro-security-update-2019-09Release NotesVendor Advisory
- https://support.deskpro.com/en/news/posts/deskpro-v2019-8-0-released-security-upRelease NotesVendor Advisory
FAQ
What is CVE-2020-11464?
CVE-2020-11464 is a vulnerability with a CVSS score of 4.3 (MEDIUM). An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve sensitive information about all users regi...
How severe is CVE-2020-11464?
CVE-2020-11464 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11464?
Check the references section above for vendor advisories and patch information. Affected products include: Deskpro Deskpro.