« Torna alla lista
RED TEAM ADVISORY // VULNERABILITY REPORT

Incorrect Authorization

Technical Description

An Incorrect Authorization / Broken Access Control vulnerability (CWE-863) was identified in Zucchetti Helpdesk Advanced (HDA) 11.2. The application backend fails to enforce role-based access controls (RBAC) and server-side authorization checks on privileged routes. This allows an authenticated low-privileged user to perform unauthorized administrative actions and interact with administrative functions by directly invoking restricted pages and backend endpoints. Impact:

Impact

An authenticated attacker with standard user privileges can view, modify, and manage critical system configurations across multiple administrative modules, leading to vertical privilege escalation and governance compromise. Affected components include:

Remediation

Upgrade to the latest release provided by the vendor to ensure all security patches are applied and workflow validation controls are enforced server-side.