Vulnerabilities > CVE-2022-45177 - Information Exposure Through Discrepancy vulnerability in Liveboxcloud Vdesk 018/031

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
liveboxcloud
CWE-203

Summary

An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

Vulnerable Configurations

Part Description Count
Application
Liveboxcloud
3

Common Weakness Enumeration (CWE)