AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-11466

MEDIUM · CVSS 4.3 EPSS 1.23%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-04-01 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2020-11466
Severity
MEDIUM
CVSS
4.3
EPSS
1.23%

Original NVD Description

An issue was discovered in Deskpro before 2019.8.0. The /api/tickets endpoint failed to properly validate a user's privilege, allowing an attacker to retrieve arbitrary information about all helpdesk tickets stored in database with numerous filters. This leaked sensitive information to unauthorized parties. Additionally, it leaked ticket authentication code, making it possible to make changes to a ticket.