Description
UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send a GET request to /html/user with 'ft[grp]' set to integer value '3' to gain super admin rights without authentication.
Problem types
CWE-862: Missing Authorization
Product status
Firmware 1.5.1 (2013.01.3)
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5575.php
www.exploit-db.com/exploits/48684 (ExploitDB-48684)
www.medivision.co.kr (UBICOD Co., Ltd. | MEDIVISION INC.)
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5575.php (Zero Security Advisory ZSL-2020-5575)
www.vulncheck.com/...uthorization-bypass-via-user-privileges (VulnCheck Advisory: UBICOD Medivision Digital Signage 1.5.1 Authorization Bypass via User Privileges)