CVE-2020-11589

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/04/2020
Last modified:
21/07/2021

Description

An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET request to a certain URL and obtain information that should be provided to authenticated users only.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cipplanner:cipace:*:*:*:*:*:*:*:* 9.1 (excluding)