Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-11680 – Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all ad

Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fails to check that a request was submitted by an administrator. Consequently, a normal user can perform actions including, but not limited to, creating/modifying the file store, creating/modifying alerts, creating/modifying users, etc.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11680

Reference (s):

  • FULLDISC:20200605 Castel NextGen DVR multiple CVEs
  • URL: http://seclists.org/fulldisclosure/2020/Jun/8
  • http://packetstormsecurity.com/files/157954/Castel-NextGen-DVR-1.0.0-Bypass-CSRF-Disclosure.html
  • https://www.securitymetrics.com/blog/attackers-known-unknown-authorization-bypass
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-5980 - The Genertel (aka com.genertel) application 2.6.0 for Android does not ve

2021-current

CVE-2019-7853 - A stored cross-site scripting vulnerability exists in Magento 2.1 prior t

2021-current

CVE-2020-1161 - A denial of service vulnerability exists when ASP.NET Core improperly han