Shop Beat Services Vulnerable To Bypass 2FA via APIs
Vulnerability Description
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-36249
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Shop Beat thanks Emirates National Oil Company Limited (ENOC) LLC for the above discovery.
References
More from Shop Beat
View All →Affected Vendor
Shop Beat
View all reports →