VYPR
Medium severity4.3NVD Advisory· Published Apr 1, 2020· Updated Jun 17, 2026

CVE-2020-11466

CVE-2020-11466

Description

An issue was discovered in Deskpro before 2019.8.0. The /api/tickets endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve arbitrary information about all helpdesk tickets stored in database with numerous filters. This leaked sensitive information to unauthorized parties. Additionally, it leaked ticket authentication code, making it possible to make changes to a ticket.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:deskpro:deskpro:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:deskpro:deskpro:*:*:*:*:*:*:*:*range: <2019.8.0
    • (no CPE)range: <2019.8.0
  • Deskpro/Deskprodescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.