An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated to the product without any specific privilege, can use the API for exporting information about all users of the system (an operation intended to only be available to the system administrator).
History

Fri, 07 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-07T20:47:55.814Z

Reserved: 2022-11-11T00:00:00.000Z

Link: CVE-2022-45180

cve-icon Vulnrichment

Updated: 2024-08-03T14:09:56.557Z

cve-icon NVD

Status : Modified

Published: 2023-04-14T14:15:10.507

Modified: 2025-02-07T21:15:10.633

Link: CVE-2022-45180

cve-icon Redhat

No data.