Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness of the TOTP is not checked properly, and can be bypassed by passing any string as the backup code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LIVEBOX Collaboration vDesk 授权问题漏洞
Vulnerability Description
LIVEBOX Collaboration vDesk是LIVEBOX公司的一个应用程序。 LIVEBOX Collaboration vDesk v018 版本及之前版本存在安全漏洞,该漏洞源于在 /login/backup_code 和 /api/v1/vdeskintegration/challenge 下可以绕过 SAML 用户的双因素身份验证。
CVSS Information
N/A
Vulnerability Type
N/A