CVE-2025-1542
CRITICALOXARI ServiceDesk <2.0.324.0 - Privilege Escalation
Title source: llmDescription
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects OXARI ServiceDesk in versions before 2.0.324.0.
Scores
CVSS v4
9.3
EPSS
0.0011
EPSS Percentile
28.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-425
Status
published
Products (1)
Infonet Projekt SA/OXARI ServiceDesk
< 2.0.324.0
Published
Mar 26, 2025
Tracked Since
Feb 18, 2026