CVE-2023-24625 Information
Mar 25, 2023
cve
Description
Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack.
Reference
https://medium.com/@cupc4k3/vulnerabilities-in-faveo-service-desk-37a63f53d896 https://cupc4k3.lol/cve-2023-24625-idor-in-faveo-service-desk-37a63f53d896 https://www.faveohelpdesk.com/servicedesk/
Share on: