An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-04-01T20:51:46
Updated: 2024-08-04T11:28:14.038Z
Reserved: 2020-04-01T00:00:00
Link: CVE-2020-11465
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2020-04-01T21:15:14.130
Modified: 2021-07-21T11:39:23.747
Link: CVE-2020-11465
Redhat
No data.