PT-2020-12710 · Cipplanner · Cipplanner Cipace
Published
2020-04-06
·
Updated
2021-07-21
·
CVE-2020-11594
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CIPPlanner CIPAce version 9.1 Build 2019092801
Description
An issue allows an unauthenticated attacker to make an API request that causes a stack error, providing the full file path.
Recommendations
For CIPPlanner CIPAce version 9.1 Build 2019092801, consider restricting access to the API endpoint that triggers the stack error until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cipplanner Cipace