Description
Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden system resources like '/#/content-creation' by manipulating client-side access restrictions.
Problem types
Authorization Bypass Through User-Controlled Key
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5611.php
www.zeroscience.mk/codes/sonybravia_idor.txt
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5611.php (Zero Science Lab Disclosure (ZSL-2020-5611))
exchange.xforce.ibmcloud.com/vulnerabilities/192607 (IBM X-Force Exchange Vulnerability Entry)
cxsecurity.com/issue/WLB-2020120031 (CXSecurity Vulnerability Listing)
packetstormsecurity.com/files/160344 (Packet Storm Security Exploit Archive)
pro.sony/ue_US/products/display-software (Sony Professional Display Software Product Page)
pro-bravia.sony.net/resources/software/bravia-signage/ (BRAVIA Signage Software Resources)
pro-bravia.sony.net (Sony BRAVIA Digital Signage Official Homepage)
www.vulncheck.com/...-client-side-protection-bypass-via-idor (VulnCheck Advisory: Sony BRAVIA Digital Signage 1.7.8 Client-Side Protection Bypass via IDOR)