Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-11464

Опубликовано: 01 апр. 2020
Источник: nvd
CVSS3: 6.5
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve sensitive information about all users registered on the system. This includes their full name, privilege, email address, phone number, etc.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:deskpro:deskpro:*:*:*:*:*:*:*:*
Версия до 2019.8.0 (исключая)

EPSS

Процентиль: 55%
0.0033
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-269

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve sensitive information about all users registered on the system. This includes their full name, privilege, email address, phone number, etc.

EPSS

Процентиль: 55%
0.0033
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-269