Vulnerabilities > CVE-2023-34923 - Incorrect Authorization vulnerability in Topdesk 12.10.12
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
NONE Summary
XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad actors with credentials to authenticate with the Identity Provider (IP) to impersonate any TOPdesk user via SAML Response manipulation.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |