CVE-2023-24625: Ladybirdweb Faveo ServiceDesk

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Faveo 5.0.1 allows remote attackers to obtain sensitive information via a modified user ID in an Insecure Direct Object Reference (IDOR) attack.

Affected products

Published 2023-03-24. Last modified 2026-06-17.