Описание
Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.
Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-36923
- https://cxsecurity.com/issue/WLB-2020120031
- https://exchange.xforce.ibmcloud.com/vulnerabilities/192607
- https://packetstormsecurity.com/files/160344
- https://pro-bravia.sony.net
- https://pro-bravia.sony.net/resources/software/bravia-signage
- https://pro.sony/ue_US/products/display-software
- https://www.vulncheck.com/advisories/sony-bravia-digital-signage-client-side-protection-bypass-via-idor
- https://www.zeroscience.mk/codes/sonybravia_idor.txt
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5611.php
Связанные уязвимости
Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.