6.5

CVE-2023-24625

Exploit
Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ladybirdweb ≫ Faveo Servicedesk Version 5.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.08% 0.609
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA-ADP 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://cupc4k3.lol/cve-2023-24625-idor-in-faveo-service-desk-37a63f53d896
Third Party Advisory
Exploit
https://medium.com/%40cupc4k3/vulnerabilities-in-faveo-service-desk-37a63f53d896
https://www.faveohelpdesk.com/servicedesk/
Product