CVE-2023-22232
Adobe Connect Improper Access Control Security feature bypass
Record summary
CVE-2023-22232 has a selected CVSS score of 5.3 (medium); EIP currently links 2 catalogued exploits and 1 Nuclei template.
Description
Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ConnectBrowse Adobe / Connect | CVE List | Through 11.4.5 | affected |
| Through 12.1.5 | affected | ||
| Through None | affected |
Proofs of concept
2Catalogued exploits
ExploitDBAdobe Connect 10 - Username DisclosureExploitDB exploitby h4shurNot analyzed1 file
ExploitDBAdobe Connect 11.4.5 - Local File DisclosureExploitDB exploitby h4shurNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMAdobe Connect < 12.1.5 - Local File DisclosureCVSS 5.3
Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction
Impact
Unauthenticated attackers can exploit improper access control to download arbitrary files through the system/download endpoint, potentially accessing sensitive Adobe Connect meeting recordings and configuration files.
Remediation
Update Adobe Connect to version 12.1.5 or later that implements proper access control checks for the system/download functionality.
Source: ProjectDiscovery