Liveboxcloud

Vdesk

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 10.06.2024 15:15:50
  • Zuletzt bearbeitet 20.03.2025 21:15:14

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application allows a u...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 10.06.2024 15:15:50
  • Zuletzt bearbeitet 21.11.2024 07:28:54

An issue was discovered in LIVEBOX Collaboration vDesk through v018. Stored Cross-site Scripting (XSS) can occur under the /api/v1/getbodyfile endpoint via the uri parameter. The web application (through its vShare functionality section) doesn't prop...

Exploit
  • EPSS 2.41%
  • Veröffentlicht 28.05.2024 20:16:12
  • Zuletzt bearbeitet 21.11.2024 07:28:53

An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShare web site section. A remote user, authenticated to the product, can arbitrarily upload potentially d...

  • EPSS 0.02%
  • Veröffentlicht 21.02.2024 16:15:49
  • Zuletzt bearbeitet 21.11.2024 07:28:53

An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arbitrary push...

  • EPSS 0.09%
  • Veröffentlicht 21.02.2024 16:15:49
  • Zuletzt bearbeitet 21.11.2024 07:28:54

An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login...

  • EPSS 0.06%
  • Veröffentlicht 21.02.2024 16:15:49
  • Zuletzt bearbeitet 28.03.2025 16:15:21

An issue was discovered in LIVEBOX Collaboration vDesk through v031. A basic XSS vulnerability exists under the /api/v1/vdeskintegration/todo/createorupdate endpoint via the title parameter and /dashboard/reminders. A remote user (authenticated to th...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 14.04.2023 14:15:10
  • Zuletzt bearbeitet 07.02.2025 17:15:22

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into a victim's account, is able to decipher a file without knowing the ke...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 14.04.2023 14:15:10
  • Zuletzt bearbeitet 07.02.2025 17:15:22

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attac...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 14.04.2023 14:15:10
  • Zuletzt bearbeitet 07.02.2025 17:15:22

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness of the TOTP...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 14.04.2023 14:15:10
  • Zuletzt bearbeitet 07.02.2025 17:15:22

An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under the 5.6.5-3/doc/{ID-FILE]/c/{N]/{C]/websocket endpoint. A malicious unauthenticated user can access cached files in the OnlyOffic...