CVE-2022-45180

An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated to the product without any specific privilege, can use the API for exporting information about all users of the system (an operation intended to only be available to the system administrator).
References
Link Resource
https://www.gruppotim.it/it/footer/red-team.html Exploit Third Party Advisory
https://www.gruppotim.it/it/footer/red-team.html Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:liveboxcloud:vdesk:*:*:*:*:*:*:*:*

History

07 Feb 2025, 21:15

Type Values Removed Values Added
References (MISC) https://www.gruppotim.it/it/footer/red-team.html - Exploit, Third Party Advisory () https://www.gruppotim.it/it/footer/red-team.html - Exploit, Third Party Advisory

19 Apr 2023, 19:28

Type Values Removed Values Added
CPE cpe:2.3:a:liveboxcloud:vdesk:*:*:*:*:*:*:*:*
First Time Liveboxcloud
Liveboxcloud vdesk
CWE NVD-CWE-noinfo
References (MISC) https://www.gruppotim.it/it/footer/red-team.html - (MISC) https://www.gruppotim.it/it/footer/red-team.html - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

14 Apr 2023, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-14 14:15

Updated : 2025-02-07 21:15


NVD link : CVE-2022-45180

Mitre link : CVE-2022-45180


JSON object : View

Products Affected

liveboxcloud

  • vdesk