CVE-2020-23451: Spiceworks

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.

Affected products

  • Spiceworks Spiceworks: up to and including 7.5.00107

Published 2020-09-15. Last modified 2026-07-09.