Vulnerabilities > Ladybirdweb > Faveo Servicedesk

DATE CVE VULNERABILITY TITLE RISK
2023-03-24 CVE-2023-24625 Authorization Bypass Through User-Controlled Key vulnerability in Ladybirdweb Faveo Servicedesk 5.0.1
Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack.
network
low complexity
ladybirdweb CWE-639
6.5