CyberRota Analysis
AI-GeneratedThe vulnerability affects Exchange products using Taskview Community versions prior to 1.56.0, allowing unauthenticated attackers to exploit the OAuth 2.0 Dynamic Client Registration endpoint. By sending a POST request, attackers can register arbitrary OAuth clients, enabling them to capture authorization codes and access tokens, which could lead to full account takeover. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access to sensitive user data.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers can send a POST request to the registration endpoint to obtain a client_id and client_secret, then craft a malicious authorization link pointing to an attacker-controlled redirect URI to capture authorization codes and exchange them for access tokens granting full API access to victim account data.