Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-45172

Опубликовано: 31 янв. 2023
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endpoint, the /api/v1/vdeskintegration/user/adduser endpoint, and the /api/v1/registration/changePasswordUser endpoint. The web application is affected by flaws in authorization logic, through which a malicious user (with no privileges) is able to perform privilege escalation to the administrator role, and steal the accounts of any users on the system.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:liveboxcloud:vdesk:*:*:*:*:*:*:*:*
Версия до 018 (исключая)

EPSS

Процентиль: 57%
0.00356
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-863
CWE-863

Связанные уязвимости

CVSS3: 9.8
github
около 3 лет назад

An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endpoint, the /api/v1/vdeskintegration/user/adduser endpoint, and the /api/v1/registration/changePasswordUser endpoint. The web application is affected by flaws in authorization logic, through which a malicious user (with no privileges) is able to perform privilege escalation to the administrator role, and steal the accounts of any users on the system.

EPSS

Процентиль: 57%
0.00356
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-863
CWE-863