An issue was discovered in LIVEBOX... CVE-2022-45169

- AV AC AU C I A
发布: 2024-02-21
修订: 2024-04-01

An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arbitrary push notification to any other user of the system. This push notification can include an (invisible) clickable link.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息