An issue was discovered in Deskpro before 2019.8.0. The /api/apps/* endpoints failed to properly validate a user's privilege, allowing an attacker to control/install helpdesk applications and leak current applications' configurations, including applications used as user sources (used for authentication). This enables an attacker to forge valid authentication models that resembles any user on the system.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:28:14.038Z
Reserved: 2020-04-01T00:00:00
Link: CVE-2020-11465

No data.

Status : Modified
Published: 2020-04-01T21:15:14.130
Modified: 2024-11-21T04:57:58.360
Link: CVE-2020-11465

No data.