Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-293w-8h49-x8x8

Опубликовано: 30 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level.

Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level.

EPSS

Процентиль: 10%
0.00035
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-288
CWE-306

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level.

EPSS

Процентиль: 10%
0.00035
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-288
CWE-306