An issue was discovered in LIVEBOX Collaboration vDesk...
Critical severity
Unreviewed
Published
Jan 31, 2023
to the GitHub Advisory Database
•
Updated Feb 16, 2023
Description
Published by the National Vulnerability Database
Jan 31, 2023
Published to the GitHub Advisory Database
Jan 31, 2023
Last updated
Feb 16, 2023
An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endpoint, the /api/v1/vdeskintegration/user/adduser endpoint, and the /api/v1/registration/changePasswordUser endpoint. The web application is affected by flaws in authorization logic, through which a malicious user (with no privileges) is able to perform privilege escalation to the administrator role, and steal the accounts of any users on the system.
References