CVE-2023-32669

Source
https://cve.org/CVERecord?id=CVE-2023-32669
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-32669.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-32669
Published
2023-10-03T12:23:24.533Z
Modified
2026-07-22T05:30:31.346528099Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Authorization Bypass on BuddyBoss
Details

Authorization bypass vulnerability in BuddyBoss 2.2.9 version, the exploitation of which could allow an authenticated user to access and rename other users' albums. This vulnerability can be exploited by changing the album identification (id).

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32669.json",
    "cna_assigner": "INCIBE",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.2.9"
                },
                {
                    "last_affected": "2.2.9"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cwe_ids": [
        "CWE-639"
    ]
}
References

Affected packages

Git / github.com/buddyboss/buddyboss-platform

Affected ranges

Type
GIT
Repo
https://github.com/buddyboss/buddyboss-platform
Events
Database specific
{
    "cpe": "cpe:2.3:a:buddyboss:buddyboss:2.2.9:*:*:*:*:wordpress:*:*",
    "extracted_events": [
        {
            "introduced": "2.2.9"
        },
        {
            "last_affected": "2.2.9"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

2.*
2.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-32669.json"