mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-05 14:58:06 +02:00
18 lines
793 B
Markdown
18 lines
793 B
Markdown
### [CVE-2020-11464](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11464)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
An issue was discovered in Deskpro before 2019.8.0. The /api/people endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve sensitive information about all users registered on the system. This includes their full name, privilege, email address, phone number, etc.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://blog.redforce.io/attacking-helpdesks-part-1-rce-chain-on-deskpro/
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|