CVE-2023-32669

Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other users' albums. This vulnerability can be exploited by changing the album identification (id).
Configurations

Configuration 1 (hide)

cpe:2.3:a:buddyboss:buddyboss:2.2.9:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 08:03

Type Values Removed Values Added
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-budyboss - Third Party Advisory () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-budyboss - Third Party Advisory

04 Oct 2023, 21:07

Type Values Removed Values Added
CWE CWE-639
References (MISC) https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-budyboss - (MISC) https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-budyboss - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:buddyboss:buddyboss:2.2.9:*:*:*:*:wordpress:*:*
First Time Buddyboss
Buddyboss buddyboss

03 Oct 2023, 13:52

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-03 13:15

Updated : 2024-11-21 08:03


NVD link : CVE-2023-32669

Mitre link : CVE-2023-32669

CVE.ORG link : CVE-2023-32669


JSON object : View

Products Affected

buddyboss

  • buddyboss
CWE
CWE-639

Authorization Bypass Through User-Controlled Key