An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated to the product without any specific privilege, can use the API for exporting information about all users of the system (an operation intended to only be available to the system administrator).
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.gruppotim.it/it/footer/red-team.html |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-04-14T00:00:00
Updated: 2024-08-03T14:09:56.557Z
Reserved: 2022-11-11T00:00:00
Link: CVE-2022-45180
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-14T14:15:10.507
Modified: 2024-11-21T07:28:54.993
Link: CVE-2022-45180
Redhat
No data.