Vulnerabilities > CVE-2020-11465 - Missing Authorization vulnerability in Deskpro

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
deskpro
CWE-862

Summary

An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system.

Vulnerable Configurations

Part Description Count
Application
Deskpro
1

Common Weakness Enumeration (CWE)