PT-2023-23944 · Buddyboss · Buddyboss
Anxo Januario Gonzales
·
Published
2023-10-03
·
Updated
2023-10-04
·
CVE-2023-32669
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
BuddyBoss version 2.2.9
Description
The issue allows an authenticated user to access and rename other users' albums by exploiting an authorization bypass vulnerability. This can be done by changing the album identification (
id).Recommendations
For BuddyBoss version 2.2.9, consider restricting access to album renaming functionality until a patch is available. As a temporary workaround, monitor album modifications closely to detect potential unauthorized changes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Buddyboss