Description
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-supplied input to execute privileged functionalities without proper authentication.
Problem types
Authorization Bypass Through User-Controlled Key
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5723.php
www.exploit-db.com/exploits/51169 (ExploitDB-51169)
web.archive.org/web/20221207074555/https://www.sound4.com/ (SOUND4 Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5723.php (Zero Science Lab Disclosure (ZSL-2022-5723))
www.vulncheck.com/...n-bypass-via-insecure-object-references (VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Authorization Bypass via Insecure Object References)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.