CVE-2024-0642
CRITICALC21 Live Encoder & Live Mosaic <5.3 - Privilege Escalation
Title source: llmDescription
Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the application as an administrator user through the application endpoint, due to lack of proper credential management.
References (1)
Core 1
Core References
Scores
CVSS v3
9.8
EPSS
0.0063
EPSS Percentile
45.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-284
Status
published
Products (1)
cires21/live_encoder
5.3
Published
Jan 17, 2024
Tracked Since
Feb 18, 2026