Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-frw8-q26x-vv93

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Adobe Connect version 11.2.2 (and earlier) is affected by a secure design principles violation vulnerability via the 'pbMode' parameter. An unauthenticated attacker could leverage this vulnerability to edit or delete recordings on the Connect environment. Exploitation of this issue requires user interaction in that a victim must publish a link of a Connect recording.

Adobe Connect version 11.2.2 (and earlier) is affected by a secure design principles violation vulnerability via the 'pbMode' parameter. An unauthenticated attacker could leverage this vulnerability to edit or delete recordings on the Connect environment. Exploitation of this issue requires user interaction in that a victim must publish a link of a Connect recording.

EPSS

Процентиль: 76%
0.00965
Низкий

Дефекты

CWE-657

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

Adobe Connect version 11.2.2 (and earlier) is affected by a secure design principles violation vulnerability via the 'pbMode' parameter. An unauthenticated attacker could leverage this vulnerability to edit or delete recordings on the Connect environment. Exploitation of this issue requires user interaction in that a victim must publish a link of a Connect recording.

CVSS3: 5.4
fstec
больше 4 лет назад

Уязвимость программы мгновенного обмена сообщениями Adobe Connect, связанная с нарушением принципов безопасного проектирования, позволяющая нарушителю выполнить обход функций безопасности

EPSS

Процентиль: 76%
0.00965
Низкий

Дефекты

CWE-657