CVE-2020-21990

Emmanuel MyDomoAtHome (MDAH) REST API REST API Domoticz ISS Gateway 0.2.40 is affected by an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this, via a specially crafted request to gain access to sensitive information.
References
Link Resource
https://www.exploit-db.com/exploits/47824 Exploit Third Party Advisory VDB Entry
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5555.php Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:domoticz:mydomoathome:0.240:*:*:*:*:node.js:*:*

Information

Published : 2021-04-29 07:15

Updated : 2021-05-07 21:57


NVD link : CVE-2020-21990

Mitre link : CVE-2020-21990


JSON object : View

CWE
CWE-863

Incorrect Authorization

Advertisement

dedicated server usa

Products Affected

domoticz

  • mydomoathome