CVE-2022-45180

An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated to the product without any specific privilege, can use the API for exporting information about all users of the system (an operation intended to only be available to the system administrator).
References
Link Resource
https://www.gruppotim.it/it/footer/red-team.html Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:liveboxcloud:vdesk:*:*:*:*:*:*:*:*

History

19 Apr 2023, 19:28

Type Values Removed Values Added
CPE cpe:2.3:a:liveboxcloud:vdesk:*:*:*:*:*:*:*:*
First Time Liveboxcloud vdesk
Liveboxcloud
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References (MISC) https://www.gruppotim.it/it/footer/red-team.html - (MISC) https://www.gruppotim.it/it/footer/red-team.html - Exploit, Third Party Advisory
CWE NVD-CWE-noinfo

14 Apr 2023, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-14 14:15

Updated : 2023-12-10 15:01


NVD link : CVE-2022-45180

Mitre link : CVE-2022-45180

CVE.ORG link : CVE-2022-45180


JSON object : View

Products Affected

liveboxcloud

  • vdesk