CVE-2022-45168
- EPSS 0.05%
- Veröffentlicht 10.06.2024 15:15:50
- Zuletzt bearbeitet 20.03.2025 21:15:14
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application allows a u...
CVE-2022-45176
- EPSS 0.34%
- Veröffentlicht 10.06.2024 15:15:50
- Zuletzt bearbeitet 21.11.2024 07:28:54
An issue was discovered in LIVEBOX Collaboration vDesk through v018. Stored Cross-site Scripting (XSS) can occur under the /api/v1/getbodyfile endpoint via the uri parameter. The web application (through its vShare functionality section) doesn't prop...
CVE-2022-45171
- EPSS 2.41%
- Veröffentlicht 28.05.2024 20:16:12
- Zuletzt bearbeitet 21.11.2024 07:28:53
An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShare web site section. A remote user, authenticated to the product, can arbitrarily upload potentially d...
CVE-2022-45169
- EPSS 0.02%
- Veröffentlicht 21.02.2024 16:15:49
- Zuletzt bearbeitet 21.11.2024 07:28:53
An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arbitrary push...
CVE-2022-45177
- EPSS 0.09%
- Veröffentlicht 21.02.2024 16:15:49
- Zuletzt bearbeitet 21.11.2024 07:28:54
An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login...
CVE-2022-45179
- EPSS 0.06%
- Veröffentlicht 21.02.2024 16:15:49
- Zuletzt bearbeitet 28.03.2025 16:15:21
An issue was discovered in LIVEBOX Collaboration vDesk through v031. A basic XSS vulnerability exists under the /api/v1/vdeskintegration/todo/createorupdate endpoint via the title parameter and /dashboard/reminders. A remote user (authenticated to th...
CVE-2022-45170
- EPSS 0.05%
- Veröffentlicht 14.04.2023 14:15:10
- Zuletzt bearbeitet 07.02.2025 17:15:22
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without knowing the ke...
CVE-2022-45173
- EPSS 0.03%
- Veröffentlicht 14.04.2023 14:15:10
- Zuletzt bearbeitet 07.02.2025 17:15:22
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attac...
CVE-2022-45174
- EPSS 0.03%
- Veröffentlicht 14.04.2023 14:15:10
- Zuletzt bearbeitet 07.02.2025 17:15:22
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness of the TOTP...
CVE-2022-45175
- EPSS 0.22%
- Veröffentlicht 14.04.2023 14:15:10
- Zuletzt bearbeitet 07.02.2025 17:15:22
An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under the 5.6.5-3/doc/{ID-FILE]/c/{N]/{C]/websocket endpoint. A malicious unauthenticated user can access cached files in the OnlyOffic...