CVE-2022-45179

An issue was discovered in LIVEBOX Collaboration vDesk through v031. A basic XSS vulnerability exists under the /api/v1/vdeskintegration/todo/createorupdate endpoint via the title parameter and /dashboard/reminders. A remote user (authenticated to the product) can store arbitrary HTML code in the reminder section title in order to corrupt the web page (for example, by creating phishing sections to exfiltrate victims' credentials).
References
Link Resource
https://www.gruppotim.it/it/footer/red-team.html Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:liveboxcloud:vdesk:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-02-21 16:15

Updated : 2024-04-01 15:52


NVD link : CVE-2022-45179

Mitre link : CVE-2022-45179

CVE.ORG link : CVE-2022-45179


JSON object : View

Products Affected

liveboxcloud

  • vdesk
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')