An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://play.google.com/store/apps/details?id=com.maxmpz.audioplayer | product |
https://powerampapp.com/ | product |
https://github.com/LianKee/SODA/blob/main/CVEs/CVE-2023-27645/CVE%20detail.md | third party advisory exploit |