PT-2025-3230 · Sonaar · Sonaar Music Mp3 Audio Player

Trương Hữu Phúc

·

Published

2025-01-02

·

Updated

2025-01-22

·

CVE-2024-56266

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar versions n/a through 5.8
Description The issue is related to a missing authorization vulnerability in the Sonaar Music MP3 Audio Player, which allows accessing functionality not properly constrained by Access Control Lists (ACLs). This means that certain functions are not correctly restricted, potentially allowing unauthorized access.
Recommendations For versions n/a through 5.8, consider restricting access to sensitive functions until a proper fix is applied, ensuring that ACLs are correctly configured to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-56266

Affected Products

Sonaar Music Mp3 Audio Player