CVE-2023-34923: Topdesk
High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.
XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad actors with credentials to authenticate with the Identity Provider (IP) to impersonate any TOPdesk user via SAML Response manipulation.
Affected products
- Topdesk Topdesk: version 12.10.12 only
Published 2023-06-22. Last modified 2026-06-17.