CVE-2022-30605: High severity wwbn avideo vulnerability
Published Aug 22, 2022
·Updated
A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
Affected Software
1 affected component
WWBN AVideo=11.6
Event History
Aug 22, 2022
CVE Published
via MITRE·06:24 PM
Data Sourced
via MITRE·06:24 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-30605?
CVE-2022-30605 is classified as a privilege escalation vulnerability.
2
How do I fix CVE-2022-30605?
To fix CVE-2022-30605, upgrade to a patched version of WWBN AVideo that addresses the vulnerability.
3
What software is affected by CVE-2022-30605?
CVE-2022-30605 affects WWBN AVideo version 11.6.
4
What can an attacker do with CVE-2022-30605?
An attacker can exploit CVE-2022-30605 to send a specially-crafted HTTP request that increases user privileges.
5
Is there a known attack vector for CVE-2022-30605?
Yes, CVE-2022-30605 can be exploited through a crafted HTTP request from an authenticated user.