An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
References
Link Resource
https://www.gruppotim.it/it/footer/red-team.html Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2024-02-21T00:00:00

Updated: 2024-02-21T15:33:49.146927

Reserved: 2022-11-11T00:00:00


Link: CVE-2022-45177

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-02-21T16:15:49.127

Modified: 2024-04-01T15:52:59.233


Link: CVE-2022-45177

JSON object: View

cve-icon Redhat Information

No data.

CWE