CVE-2023-34923

HIGH

TOPdesk 12.10.12 - Authenticated User Impersonation via SAML Response Manipulation

Title source: llm
STIX 2.1

Description

XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad actors with credentials to authenticate with the Identity Provider (IP) to impersonate any TOPdesk user via SAML Response manipulation.

Scores

CVSS v3 8.1
EPSS 0.0074
EPSS Percentile 49.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (1)
topdesk/topdesk 12.10.12
Published Jun 22, 2023
Tracked Since Feb 18, 2026