CVE-2020-11594: Cipplanner Cipace
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that causes a stack error to be shown providing the full file path.
Affected products
- Cipplanner Cipace: before 9.1 (fixed in 9.1)
Published 2020-04-06. Last modified 2026-06-17.