PT-2022-12460 · Unknown · Vivoh Webinar Manager
Shubham Agrawal
·
Published
2022-03-30
·
Updated
2022-04-06
·
CVE-2021-45900
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Vivoh Webinar Manager versions prior to 3.6.3.0
Description
The issue is related to improper API authentication. When a user logs in to the administration configuration web portlet, a VIVOH AUTH cookie is assigned for unique identification. However, certain APIs can be executed without proper authentication, allowing an attacker to impersonate a victim and make state-changing requests on their behalf.
Recommendations
For versions prior to 3.6.3.0, update to version 3.6.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive APIs to minimize the risk of exploitation. Avoid using APIs that do not require proper authentication until the issue is resolved.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vivoh Webinar Manager