vendor:
IMPACT/Pulse/First/Eco/BigVoice4/BigVoice2/Stream/WM2 (Kantar Media)
by:
LiquidWorm
7.5
CVSS
HIGH
Insecure Direct Object Reference
639
CWE
Product Name: IMPACT/Pulse/First/Eco/BigVoice4/BigVoice2/Stream/WM2 (Kantar Media)
Affected Version From: 1.1/2.15
Affected Version To: 1.16
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: FM/HD Radio Processing, Voice Processing, Web-Audio Streaming, Watermarking
2020
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x – Authorization Bypass (IDOR)
The application is vulnerable to insecure direct object references that occur when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypaas the authentication and authorization of the application and gain access to unauthorized functionality.
Mitigation:
Ensure that user-supplied input is not used to directly access objects in the application.