CVE-2024-5168

Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthenticated user to bypass authentication entirely and execute arbitrary API requests against the web application.
Configurations

No configuration.

History

21 Nov 2024, 09:47

Type Values Removed Values Added
References () https://www.incibe.es/en/incibe-cert/notices/aviso/improper-access-control-vulnerability-prodys-quantum-audio-codec - () https://www.incibe.es/en/incibe-cert/notices/aviso/improper-access-control-vulnerability-prodys-quantum-audio-codec -
Summary
  • (es) Vulnerabilidad de control de acceso inadecuado en el códec Quantum Audio de Prodys que afecta a las versiones 2.3.4t e inferiores. Esta vulnerabilidad podría permitir que un usuario no autenticado omita la autenticación por completo y ejecute solicitudes API arbitrarias en la aplicación web.

23 May 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-23 13:15

Updated : 2024-11-21 09:47


NVD link : CVE-2024-5168

Mitre link : CVE-2024-5168

CVE.ORG link : CVE-2024-5168


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control