vendor:
Medivision Digital Signage
by:
LiquidWorm
5.5
CVSS
MEDIUM
Authorization Bypass
IDOR
CWE
Product Name: Medivision Digital Signage
Affected Version From: Firmware 1.5.1
Affected Version To: Firmware 1.5.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Ubuntu
2020
UBICOD Medivision Digital Signage 1.5.1 – Authorization Bypass
The application suffers from a privilege escalation vulnerability. Normal user can elevate his/her privileges by navigating to /html/user (via IDOR) page sending an HTTP GET request setting the parameter 'ft[grp]' to integer value '3' gaining super admin rights.
Mitigation:
The vendor should validate the user's privileges on the server-side and restrict unauthorized access.