Liveboxcloud's vulnerability profile centers on its vDesk virtual desktop platform, where disclosures cluster around authentication and authorization weaknesses, including improper authentication mechanisms, authorization bypass conditions, and cross-site scripting vulnerabilities in web-facing components. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Liveboxcloud over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45172CRITICAL An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endpoint, the /api/v1/vdeskintegrat | Jan 31, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-45174CRITICAL An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /a | Apr 14, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-45173CRITICAL An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because | Apr 14, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-45178HIGH An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdeskintegration/saml/user/createorupdate endpoint, the /setting | Apr 14, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-45171HIGH An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShare web site section. A remote us | May 28, 2024 | 8.8 | 23 | NO | NO |
CVE-2022-45177HIGH An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the | Feb 21, 2024 | 7.5 | 22 | NO | NO |
CVE-2022-45180MEDIUM An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated | Apr 14, 2023 | 6.5 | 22 | NO | NO |
CVE-2022-45175MEDIUM An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under the 5.6.5-3/doc/{ID-FILE]/c/{N]/{C]/websocket endpoint. A m | Apr 14, 2023 | 6.5 | 21 | NO | NO |
CVE-2022-45170MEDIUM An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/vencrypt/decrypt/file endpoint. A malicious user, logged into | Apr 14, 2023 | 6.5 | 21 | NO | NO |
CVE-2022-45168MEDIUM An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /login/backup_code endpoint and the /api/v1/vdeskinte | Jun 10, 2024 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Liveboxcloud.
Media articles that mention a CVE ID that affects a product developed by Liveboxcloud — matched by CVE ID, not by vendor name.