CVE-2020-11595
- EPSS 0.97%
- Veröffentlicht 06.04.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 04:58:12
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and obtain the upload folder path that includes the hostname in a UNC path.
CVE-2020-11594
- EPSS 0.71%
- Veröffentlicht 06.04.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 04:58:11
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that causes a stack error to be shown providing the full file path.
CVE-2020-11593
- EPSS 1.11%
- Veröffentlicht 06.04.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 04:58:11
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to send emails from a customer trusted email address.
CVE-2020-11592
- EPSS 0.97%
- Veröffentlicht 06.04.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 04:58:11
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and get the columns of a specific table within the CIP database.
CVE-2020-11591
- EPSS 0.88%
- Veröffentlicht 06.04.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 04:58:11
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and obtain the full application path along with the customer name.
CVE-2020-11590
- EPSS 0.65%
- Veröffentlicht 06.04.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 04:58:11
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to HealthPage.aspx and obtain the internal server name.
CVE-2020-11589
- EPSS 0.92%
- Veröffentlicht 06.04.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 04:58:11
An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET request to a certain URL and obtain information that should be provided to authenticated users only.
CVE-2020-11588
- EPSS 0.88%
- Veröffentlicht 06.04.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:11
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to two files that contain customer data and application paths.