First published: Wed Apr 01 2020(Updated: )
An issue was discovered in Deskpro before 2019.8.0. The /api/tickets endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve arbitrary information about all helpdesk tickets stored in database with numerous filters. This leaked sensitive information to unauthorized parties. Additionally, it leaked ticket authentication code, making it possible to make changes to a ticket.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Deskpro Deskpro | <2019.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-11466.
The severity of CVE-2020-11466 is high with a CVSS score of 4.3.
The affected software for CVE-2020-11466 is Deskpro before version 2019.8.0.
An attacker can exploit CVE-2020-11466 by leveraging the /api/tickets endpoint to retrieve arbitrary information about all helpdesk tickets stored in the database.
Yes, a fix is available for CVE-2020-11466 in Deskpro version 2019.8.0 and later.