Junglewise Threat Intelligence

CVE-2024-13068: Akinsoft LimonDesk forceful browsing via origin validation error

CVE-2024-13068 · Severity: high · CVSS 7.3 · Published 2025-09-03

Technologies: AKINSOFT LimonDesk. Vendors: AKINSOFT.

Executive brief

Akinsoft LimonDesk, a customer support and help desk software, contains a security flaw that allows unauthorized access to restricted areas of the application. By guessing or directly entering specific web addresses, an attacker can bypass intended navigation controls to view sensitive information or perform unauthorized actions. This could lead to the exposure of customer data or disruption of support operations.

Technical details

An Origin Validation Error (CWE-346) exists in Akinsoft LimonDesk versions s1.02.14 through v1.02.17. The vulnerability allows for 'Forceful Browsing,' where an unauthenticated remote attacker can access restricted pages or directories by manually entering URLs that are not linked within the application's visible interface. This occurs because the application fails to properly validate the origin or authorization state of requests for specific internal resources. Attackers can exploit this to gain unauthorized access to sensitive data or administrative functions. A patch is available in version 1.02.17.

Affected products

  • Akinsoft LimonDesk s1.02.14 to v1.02.17

Timeline

  • 2025-09-03: advisory: Initial publication of CVE-2024-13068
  • 2026-01-06: other: CVE record updated by TR-CERT

References

Related threats