2024-12-08 03:06:42 +00:00

88 lines
2.9 KiB
JSON

{
"id": "CVE-2022-45179",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-02-21T16:15:49.173",
"lastModified": "2024-11-21T07:28:54.830",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in LIVEBOX Collaboration vDesk through v031. A basic XSS vulnerability exists under the /api/v1/vdeskintegration/todo/createorupdate endpoint via the title parameter and /dashboard/reminders. A remote user (authenticated to the product) can store arbitrary HTML code in the reminder section title in order to corrupt the web page (for example, by creating phishing sections to exfiltrate victims' credentials)."
},
{
"lang": "es",
"value": "Se descubri\u00f3 un problema en LIVEBOX Collaboration vDesk hasta v031. Existe una vulnerabilidad XSS b\u00e1sica en el endpoint /api/v1/vdeskintegration/todo/createorupdate a trav\u00e9s del par\u00e1metro title y /dashboard/reminders. Un usuario remoto (autenticado en el producto) puede almacenar c\u00f3digo HTML arbitrario en el t\u00edtulo de la secci\u00f3n de recordatorio para corromper la p\u00e1gina web (por ejemplo, creando secciones de phishing para extraer las credenciales de las v\u00edctimas)."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.3,
"impactScore": 2.7
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:liveboxcloud:vdesk:*:*:*:*:*:*:*:*",
"versionEndIncluding": "031",
"matchCriteriaId": "258E49A5-480F-463A-A7AE-891A918FA851"
}
]
}
]
}
],
"references": [
{
"url": "https://www.gruppotim.it/it/footer/red-team.html",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://www.gruppotim.it/it/footer/red-team.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory"
]
}
]
}