CVE-2025-1542

CRITICAL

OXARI ServiceDesk <2.0.324.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects OXARI ServiceDesk in versions before 2.0.324.0.

Scores

CVSS v4 9.3
EPSS 0.0011
EPSS Percentile 28.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-425
Status published
Products (1)
Infonet Projekt SA/OXARI ServiceDesk < 2.0.324.0
Published Mar 26, 2025
Tracked Since Feb 18, 2026