Security Advisory

CVE-2023-32669

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-10-03 12:23:24
Last updated 2024-09-06 14:10:21
Assigner INCIBE
CVSS score 5.4
State PUBLISHED

Description

Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other users' albums. This vulnerability can be exploited by changing the album identification (id).