vendor:
Eibiz i-Media Server Digital Signage
by:
LiquidWorm
8.8
CVSS
HIGH
Privilege Escalation / Account Takeover
264
CWE
Product Name: Eibiz i-Media Server Digital Signage
Affected Version From: 3.8.0
Affected Version To: 3.8.0
Patch Exists: YES
Related CWE: N/A
CPE: a:eibiz:i-media_server_digital_signage
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows Server 2016, Windows Server 2012 R2, Windows Server 2008 R2, Apache Flex, Apache Tomcat/6.0.14, Apache-Coyote/1.1, BlazeDS Application
2020
Eibiz i-Media Server Digital Signage 3.8.0 – Privilege Escalation
The application suffers from an unauthenticated remote privilege escalation and account takeover vulnerability that can be triggered by directly calling the updateUser object (part of ActionScript object graphs), effectively elevating to an administrative role or taking over an existing account by modifying the settings.
Mitigation:
Update to the latest version of Eibiz i-Media Server Digital Signage