Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cjwx-wwmv-rqgc

Опубликовано: 21 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arbitrary push notification to any other user of the system. This push notification can include an (invisible) clickable link.

An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arbitrary push notification to any other user of the system. This push notification can include an (invisible) clickable link.

EPSS

Процентиль: 5%
0.00021
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 5.4
nvd
почти 2 года назад

An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arbitrary push notification to any other user of the system. This push notification can include an (invisible) clickable link.

EPSS

Процентиль: 5%
0.00021
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-601