PT-2026-97803 · Blackcandy Org · Black Candy
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Black Candy versions prior to 3.2.2
Description
An issue exists where playlist search queries are not scoped to the authenticated session user. This allows any authenticated user to enumerate all playlists on the instance. Attackers can use blank or targeted search parameters via the 'SearchController' or 'Search::PlaylistsController' endpoints to retrieve playlist names belonging to other users without authorization.
Recommendations
Update to a version newer than 3.2.1.
Restrict access to the 'SearchController' and 'Search::PlaylistsController' endpoints to minimize the risk of unauthorized data retrieval.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Black Candy