ZeroHour

Vulnerabilities

13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-45168
+1 in the same advisory: …45176
An issue was discovered in LIVEBOX Collaboration vDesk through v018.

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/createbackupcodes endpoint, because the application allows a user to generate or regenerate the backup codes before checking the TOTP.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • liveboxcloud vdesk
CVE-2022-45171
An issue was discovered in LIVEBOX Collaboration vDesk through v018.

An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShare web site section. A remote user, authenticated to the product, can arbitrarily upload potentially dangerous files without restrictions.

NVD description · AI analysis pending
8.8<1% PoC
  • liveboxcloud vdesk
CVE-2022-45177
+2 in the same advisory: …45179 …45169
An issue was discovered in LIVEBOX Collaboration vDesk through v031.

An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

NVD description · AI analysis pending
7.5
group max
<1%
  • liveboxcloud vdesk
CVE-2022-45174
An issue was discovered in LIVEBOX Collaboration vDesk through v018.

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness of the TOTP is not checked properly, and can be bypassed by passing any string as the backup code.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • liveboxcloud vdesk
CVE-2022-45172
An issue was discovered in LIVEBOX Collaboration vDesk before v018.

An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endpoint, the /api/v1/vdeskintegration/user/adduser endpoint, and the /api/v1/registration/changePasswordUser endpoint. The web application is affected by flaws in authorization logic, through which a malicious user (with no privileges) is able to perform privilege escalation to the administrator role, and steal the accounts of any users on the system.

NVD description · AI analysis pending
9.81% PoC
  • liveboxcloud vdesk