Critical severity9.8NVD Advisory· Published Jan 31, 2023· Updated Jun 17, 2026
CVE-2022-45172
CVE-2022-45172
Description
An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endpoint, the /api/v1/vdeskintegration/user/adduser endpoint, and the /api/v1/registration/changePasswordUser endpoint. The web application is affected by flaws in authorization logic, through which a malicious user (with no privileges) is able to perform privilege escalation to the administrator role, and steal the accounts of any users on the system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- LIVEBOX Collaboration/vDeskdescription
Patches
Vulnerability mechanics
References
1- www.gruppotim.it/it/footer/red-team.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.