Vulnerabilities > CVE-2020-11589 - Authorization Bypass Through User-Controlled Key vulnerability in Cipplanner Cipace 6.80
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET request to a certain URL and obtain information that should be provided to authenticated users only.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |