OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, allowing any user to upload files.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://github.com/davidguva/OpenVidReview | product |
https://github.com/davidguva/OpenVidReview/blob/main/routes/upload.js | product |
https://github.com/b1d0ws/CVEs/blob/main/CVE-2024-46054.md | third party advisory |