Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdeskintegration/saml/user/createorupdate endpoint, the /settings/guest-settings endpoint, the /settings/samlusers-settings endpoint, and the /settings/users-settings endpoint. A malicious user (already logged in as a SAML User) is able to achieve privilege escalation from a low-privilege user (FGM user) to an administrative user (GGU user), including the administrator, or create new users even without an admin role.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LIVEBOX Collaboration vDesk 安全漏洞
Vulnerability Description
LIVEBOX Collaboration vDesk是LIVEBOX公司的一个应用程序。 LIVEBOX Collaboration vDesk v018 版本及之前版本存在安全漏洞,该漏洞源于 /api/v1/vdeskintegration/saml/user/createorupdate 、/settings/guest-settings 、/settings/samlusers-settings 和 /settings/users-settings 下存在损坏的访问控制。
CVSS Information
N/A
Vulnerability Type
N/A