PT-2023-23944 · Buddyboss · Buddyboss
Anxo Januario Gonzales
·
Publicado
2023-10-03
·
Atualizado
2023-10-04
·
CVE-2023-32669
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
BuddyBoss version 2.2.9
Description
The issue allows an authenticated user to access and rename other users' albums by exploiting an authorization bypass vulnerability. This can be done by changing the album identification (
id).Recommendations
For BuddyBoss version 2.2.9, consider restricting access to album renaming functionality until a patch is available. As a temporary workaround, monitor album modifications closely to detect potential unauthorized changes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IDOR
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Buddyboss