VYPR
Critical severity9.8NVD Advisory· Published Jan 31, 2023· Updated Jun 17, 2026

CVE-2022-45172

CVE-2022-45172

Description

An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endpoint, the /api/v1/vdeskintegration/user/adduser endpoint, and the /api/v1/registration/changePasswordUser endpoint. The web application is affected by flaws in authorization logic, through which a malicious user (with no privileges) is able to perform privilege escalation to the administrator role, and steal the accounts of any users on the system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • LIVEBOX Collaboration/vDeskdescription
  • LIVEBOX/vDeskllm-fuzzy
    Range: <018

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.