Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g759-2x5w-f89c

Опубликовано: 21 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

EPSS

Процентиль: 30%
0.00114
Низкий

7.5 High

CVSS3

Дефекты

CWE-203
CWE-94

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

EPSS

Процентиль: 30%
0.00114
Низкий

7.5 High

CVSS3

Дефекты

CWE-203
CWE-94