CVE-2025-1542
CRITICALOXARI ServiceDesk <2.0.324.0 - Privilege Escalation
Title source: llmDescription
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects OXARI ServiceDesk in versions before 2.0.324.0.
References (2)
Core 2
Core References
Various Sources
https://cert.pl/en/posts/2025/03/CVE-2025-1542/
Various Sources
https://www.oxari.com/en/product/oxari-servicedesk
Scores
CVSS v4
9.3
EPSS
0.0033
EPSS Percentile
24.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-425
Status
published
Products (1)
Infonet Projekt SA/OXARI ServiceDesk
< 2.0.324.0
Published
Mar 26, 2025
Tracked Since
Feb 18, 2026