CVE-2020-11589: Cipplanner Cipace
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET request to a certain URL and obtain information that should be provided to authenticated users only.
Affected products
- Cipplanner Cipace: before 9.1 (fixed in 9.1)
Published 2020-04-06. Last modified 2026-06-17.