CVE-2024-56266
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jan 2, 2025
Updated: Jan 22, 2025
CWE ID 862
Summary
CVE-2024-56266 is a vulnerability affecting the Sonaar Music MP3 Audio Player for Music, Radio & Podcast. It involves a Missing Authorization issue, where functionality is not adequately constrained by Access Control Lists (ACLs). This security flaw allows unauthorized access to certain features of the software. The vulnerability is present in versions 5.8 and below of the MP3 Audio Player by Sonaar. Successful exploitation of this vulnerability could potentially allow attackers to gain unintended access and manipulate the player's functionality.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.