PT-2022-21451 · Wwbn · Avideo
Claudio Bozzato
·
Published
2022-08-22
·
Updated
2022-08-24
·
CVE-2022-32769
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
WWBN AVideo versions 11.6
Description
Multiple authentication bypass issues exist in the objects id handling functionality. A specially-crafted HTTP request by an authenticated user can lead to unauthorized access and takeover of resources. This issue exists in the Playlists plugin, allowing an attacker to bypass authentication by guessing a sequential ID, enabling them to take over another user's playlists.
Recommendations
For version 11.6, consider disabling the Playlists plugin until a patch is available to prevent exploitation.
As a temporary workaround, restrict access to the sequential ID handling functionality to minimize the risk of unauthorized access.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo