CVE-2022-36249
Summary
| CVE | CVE-2022-36249 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-30 20:15:00 UTC |
| Updated | 2023-06-02 20:50:00 UTC |
| Description | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Shopbeat | Shop Beat Media Player | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Shop Beat - Giving Your Shop A Beat | MISC | www.shopbeat.co.za | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Shop Beat thanks Emirates National Oil Company Limited (ENOC) LLC for the above discovery.
There are currently no legacy QID mappings associated with this CVE.