Impact
A broken access control flaw exists in Ladybird Web Solution’s Faveo Helpdesk version 2.0.3. The v1 REST API fails to verify ticket ownership before returning ticket details, allowing any authenticated user to read the entire conversation history of any ticket, including internal agent notes that may contain sensitive information. This results in a confidentiality breach of customer records and internal communications.
Affected Systems
The vulnerability affects Ladybird Web Solution Faveo Helpdesk version 2.0.3, specifically the endpoints of the v1 REST API that provide ticket details. No other versions or components are listed as affected in the current CNA data.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so the exact exploitation probability cannot be quantified, but the flaw is exploitable by any authenticated user using normal API calls, making exploitation straightforward. The vulnerability is not listed in CISA’s KEV catalog as of the last update. Prompt remediation is recommended to protect customer and agent data.
OpenCVE Enrichment