Files
CVEs-PoC/2020/CVE-2020-8145.md
T
2024-05-25 21:48:12 +02:00

18 lines
1.1 KiB
Markdown

### [CVE-2020-8145](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8145)
![](https://img.shields.io/static/v1?label=Product&message=UniFi%20Video%20Controller%20(for%20Windows%207%2F8%2F10%20x64)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Privilege%20Escalation%20(CAPEC-233)&color=brighgreen)
### Description
The UniFi Video Server (Windows) web interface configuration restore functionality at the “backup” and “wizard” endpoints does not implement sufficient privilege checks. Low privileged users, belonging to the PUBLIC_GROUP or CUSTOM_GROUP groups, can access these endpoints and overwrite the current application configuration. This can be abused for various purposes, including adding new administrative users. Affected Products: UniFi Video Controller v3.9.3 (for Windows 7/8/10 x64) and prior. Fixed in UniFi Video Controller v3.9.6 and newer.
### POC
#### Reference
- https://hackerone.com/reports/329659
#### Github
No PoCs found on GitHub currently.