vendor:
Adobe Connect
by:
h4shur
7.5
CVSS
HIGH
Improper Access Control
284
CWE
Product Name: Adobe Connect
Affected Version From: 11.4.2005
Affected Version To: 12.1.2005
Patch Exists: YES
Related CWE: CVE-2023-22232
CPE: a:adobe:connect:11.4.5
Platforms Tested: Windows 10 & Google Chrome, kali linux & firefox
2021.01.16-2023.02.17
Adobe Connect 11.4.5 – Local File Disclosure
Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction.
Mitigation:
Developers should ensure that access control checks are in place to prevent unauthorized access to sensitive files.