CVE-2022-36249
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published May 30, 2023
Updated: Jan 13, 2025
CWE ID 306
CWE ID 288
Summary
CVE-2022-36249 is a cybersecurity vulnerability affecting Shop Beat Media Player 2.5.95 to 3.2.57 by Shop Beat Solutions (Pty) Ltd. This issue allows an attacker to bypass Two-Factor Authentication (2FA) during API access. After successfully logging in, the attacker can directly utilize the bearer token or jsession ID instead of entering the required 2FA code. As a result, 2FA is bypassed at the API level, potentially exposing sensitive data to unauthorized access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.