CVE-2023-32669: Authorization Bypass on BuddyBoss
Published Oct 3, 2023
·Updated
Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other users' albums. This vulnerability can be exploited by changing the album identification (id).
Affected Software
1 affected component
Buddyboss Buddyboss Wordpress=2.2.9
Event History
Oct 3, 2023
CVE Published
via MITRE·12:23 PM
Data Sourced
via MITRE·12:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-32669?
CVE-2023-32669 is an authorization bypass vulnerability in BuddyBoss 2.2.9 version that allows an authenticated user to access and rename other users' albums.
2
How can this vulnerability be exploited?
This vulnerability can be exploited by changing the album identification (id).
3
How severe is CVE-2023-32669?
CVE-2023-32669 has a severity rating of medium with a CVSS score of 5.4.
4
What software version is affected by CVE-2023-32669?
BuddyBoss version 2.2.9 is affected by CVE-2023-32669.
5
How can I fix CVE-2023-32669?
Update BuddyBoss to a version that is not affected by CVE-2023-32669.