PT-2022-21204 · Wwbn · Avideo
Claudio Bozzato
·
Published
2022-08-22
·
Updated
2022-08-26
·
CVE-2022-32282
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WWBN AVideo versions 11.6
WWBN AVideo dev master commit 3f7c0364
Description
An issue exists in the login functionality due to an improper password check. This allows an attacker with a user's password hash to directly log into the account, resulting in increased privileges.
Recommendations
For WWBN AVideo version 11.6, update the login functionality to properly check passwords.
For WWBN AVideo dev master commit 3f7c0364, apply a patch to fix the improper password check issue.
As a temporary workaround, consider restricting access to sensitive areas of the application until a proper fix is applied.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Avideo