Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown
CVE-2022-45176
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
An issue was discovered in LIVEBOX Collaboration vDesk through v018. Stored Cross-site Scripting (XSS) can occur under the /api/v1/getbodyfile endpoint via the uri parameter. The web application (through its vShare functionality section) doesn't properly check parameters, sent in HTTP requests as input, before saving them on the server. In addition, crafted JavaScript content can then be reflected back to the end user and executed by the web browser.
0
Attacker Value
Unknown
CVE-2022-45168
Disclosure Date: June 10, 2024 (last updated February 26, 2025)
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application allows a user to generate or regenerate the backup codes before checking the TOTP.
0
Attacker Value
Unknown
CVE-2022-45171
Disclosure Date: May 28, 2024 (last updated February 26, 2025)
An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShare web site section. A remote user, authenticated to the product, can arbitrarily upload potentially dangerous files without restrictions.
0
Attacker Value
Unknown
CVE-2024-0916
Disclosure Date: April 25, 2024 (last updated February 26, 2025)
Unauthenticated file upload allows remote code execution.
This issue affects UvDesk Community: from 1.0.0 through 1.1.3.
0
Attacker Value
Unknown
CVE-2024-3137
Disclosure Date: April 02, 2024 (last updated February 26, 2025)
Improper Privilege Management in uvdesk/community-skeleton
0
Attacker Value
Unknown
CVE-2022-45179
Disclosure Date: February 21, 2024 (last updated February 26, 2025)
An issue was discovered in LIVEBOX Collaboration vDesk through v031. A basic XSS vulnerability exists under the /api/v1/vdeskintegration/todo/createorupdate endpoint via the title parameter and /dashboard/reminders. A remote user (authenticated to the product) can store arbitrary HTML code in the reminder section title in order to corrupt the web page (for example, by creating phishing sections to exfiltrate victims' credentials).
0
Attacker Value
Unknown
CVE-2022-45177
Disclosure Date: February 21, 2024 (last updated February 26, 2025)
An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
0
Attacker Value
Unknown
CVE-2022-45169
Disclosure Date: February 21, 2024 (last updated February 26, 2025)
An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arbitrary push notification to any other user of the system. This push notification can include an (invisible) clickable link.
0
Attacker Value
Unknown
CVE-2023-37636
Disclosure Date: October 23, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.
0
Attacker Value
Unknown
CVE-2023-39147
Disclosure Date: August 01, 2023 (last updated February 25, 2025)
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.
0