CVE-2025-1542 Details
Description
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects OXARI ServiceDesk in versions before 2.0.324.0.
A vulnerability in the OXARI ServiceDesk application, all versions prior to 2.0.324.0, allows an attacker with guest access or an unprivileged account to gain unauthorized administrative permissions. This improper permission control could be exploited to manipulate application features or access sensitive information.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 26, 2025CISA-ADP
Assessed Mar 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/en/posts/2025/03/CVE-2025-1542/ | [email protected] | AdvisoryVendor |
| https://www.oxari.com/en/product/oxari-servicedesk | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-425 | Direct Request ('Forced Browsing') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Infonet Projekt SA OXARI ServiceDesk | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 3, 2025 | CVE Modified | [email protected] |
| Mar 26, 2025 | New CVE Received | [email protected] |
Volerion