PT-2024-31402 · Unknown · Ringer Server
Superior126
·
Published
2024-09-04
·
Updated
2024-09-05
·
CVE-2024-45050
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ringer server versions prior to 1.3.1
Description
The issue concerns the messages loading route in the Ringer server, where it fails to verify if the user loading a conversation is actually a member of that conversation. This allows any user with a Lif Account to load any conversation between two users without permission. The problem was solved in version 1.3.1.
Recommendations
For versions prior to 1.3.1, update to version 1.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the messages loading route until the patch is applied.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ringer Server