CVE-2020-1018 is an information disclosure vulnerability affecting Microsoft Dynamics Business Central/NAV on-premise. It allows an attacker to view masked field data when records are displayed as a chart page. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network without user interaction, leading to a complete compromise of confidentiality. There is no public exploit code available, nor is it listed in CISA's KEV catalog, suggesting it is not actively exploited. However, it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:dynamics_365_business_central:-:*:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:dynamics_365_business_central:2019:spring_update:*:*:*:*:*:* | ||
2015CPE matchmatch criteria | cpe:2.3:a:microsoft:dynamics_nav:2015:*:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:dynamics_nav:2016:*:*:*:*:*:*:* | ||
2017CPE matchmatch criteria | cpe:2.3:a:microsoft:dynamics_nav:2017:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.