An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated to the product without any specific privilege, can use the API for exporting information about all users of the system (an operation intended to only be available to the system administrator).
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.gruppotim.it/it/footer/red-team.html |
![]() ![]() |
History
Fri, 07 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-07T20:47:55.814Z
Reserved: 2022-11-11T00:00:00.000Z
Link: CVE-2022-45180

Updated: 2024-08-03T14:09:56.557Z

Status : Modified
Published: 2023-04-14T14:15:10.507
Modified: 2025-02-07T21:15:10.633
Link: CVE-2022-45180

No data.