CVE Published: 21/04/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: DEVOLUTIONS |
Vendor: Devolutions |
Product: Devolutions Server Status : PUBLISHED
CVE-2023-2118 Description
Insufficient access control in support ticket feature in Devolutions Server 2023.1.5.0 and below allows an authenticated attacker to send support tickets and download diagnostic files via specific endpoints.