An Incorrect Authorization / Broken Access Control vulnerability (CWE-863) was identified in Zucchetti Helpdesk Advanced (HDA) 11.2. The application backend fails to enforce role-based access controls (RBAC) and server-side authorization checks on privileged routes. This allows an authenticated low-privileged user to perform unauthorized administrative actions and interact with administrative functions by directly invoking restricted pages and backend endpoints. Impact:
An authenticated attacker with standard user privileges can view, modify, and manage critical system configurations across multiple administrative modules, leading to vertical privilege escalation and governance compromise. Affected components include:
Upgrade to the latest release provided by the vendor to ensure all security patches are applied and workflow validation controls are enforced server-side.