VYPR

faveo-helpdesk

by Faveosuite

CVEs (1)

  • CVE-2026-72554MedAug 11, 2026
    risk 0.42cvss 6.5epss

    A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via the v1 REST API. The API verifies the existence of the requested ticket but not ownership,…