CVE Database
/

CVE-2022-36249

Back to search

CVE-2022-36249

Published: May 30, 2023

Modified: Jan 13, 2025

PUBLISHED

Description

Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level.

VendorProductVersions

Shop Beat

studio

affected
studio - < 3.2.57

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now