vendor:
Serviio
by:
Gjoko 'LiquidWorm' Krstic
7,5
CVSS
HIGH
Unauthenticated Password Modification Vulnerability
287
CWE
Product Name: Serviio
Affected Version From: 1.8.0.0 PRO
Affected Version To: 1.6.1
Patch Exists: YES
Related CWE: N/A
CPE: a:petr_nejedly:serviio
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7, Mac OS X, Linux
2017
Serviio PRO 1.8 DLNA Media Streaming Server REST API Arbitrary Password Change
The version of Serviio installed on the remote Windows/Linux host is affected by an unauthenticated password modification vulnerability due to improper access control enforcement of the Configuration REST API. A remote attacker can exploit this, via a specially crafted request, to change the login password for the mediabrowser protected page.
Mitigation:
Ensure that access control enforcement is properly implemented for the Configuration REST API.