← Back

CVE-2022-36249

nvd nist
Published: May 30, 2023Modified: Jan 13, 2025

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level.

Affected (1)

1 product
Shop Beat Media Player
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.5.95 to 3.2.57

References (2)

Source: support@shopbeat.co.za
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.