CVE-2023-22232
published 2023-02-17CVE-2023-22232: Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security…
PriorityP262medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EXPLOIT
EPSS
81.88%
99.6th percentile
Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | connect | 11.0 – 11.4.5 | — |
| adobe | connect | 12.0 – 12.1.5 | — |
| adobe | connect | unspecified – 11.4.5 | — |
Detection & IOCsextracted from sources · hover to see the quote
url/system/download?download-url=/_a7/p49dm7f4qjyt/output/&name=exam.pdf
path/system/download
urlhttps://target.com/[folder]/download?output=output&download_type=[Suffix]&ffn=[URL]&baseContentUrl=[base file folder]↗
- →Detect exploitation attempts by monitoring HTTP GET requests to the /system/download endpoint with parameters 'download-url' and 'name', especially when no authentication is present. Responses containing 'Save to My Computer', 'Click to Download', and a filename in the body with HTTP 200 indicate successful exploitation.
- →Monitor for unauthenticated GET requests to paths matching /*/download with query parameters 'download-url' (pointing to internal paths) and 'name' (specifying a file extension), which indicate LFD exploitation attempts. ↗
- →Monitor for unauthenticated GET requests to paths matching /*/download with query parameters 'ffn', 'download_type', and 'baseContentUrl', which indicate multi-file ZIP download exploitation attempts. ↗
- →Monitor unauthenticated access to /system/help/support for username disclosure attempts on Adobe Connect instances. ↗
- ·The Nuclei template probe path uses a hardcoded internal Adobe Connect path as the download-url value; real exploitation will use attacker-controlled paths pointing to sensitive server files (e.g., /etc/passwd via path traversal).
- ·The vulnerability affects Adobe Connect 11.4.5 and earlier AND 12.1.5 and earlier (two separate version branches); detection rules should account for both branches. ↗
- ·Exploitation requires no user interaction and no authentication (PR:N, UI:N per CVSS), meaning any unauthenticated HTTP request to the vulnerable endpoint is a valid attack vector.
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Adobe Connect 11.4.5 - Local File Disclosure
exploitdb·2023-04-08·CVSS 5.3
CVE-2023-22232 [MEDIUM] Adobe Connect 11.4.5 - Local File Disclosure
Adobe Connect 11.4.5 - Local File Disclosure
---
# Title: Adobe Connect 11.4.5 - Local File Disclosure
# Author: h4shur
# date:2021.01.16-2023.02.17
# CVE: CVE-2023-22232
# Vendor Homepage: https://www.adobe.com
# Software Link: https://www.adobe.com/products/adobeconnect.html
# Version: 11.4.5 and earlier, 12.1.5 and earlier
# User interaction: None
# Tested on: Windows 10 & Google Chrome, kali linux & firefox
### Summary:
Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature.
Exploitation of this issue does not require user interaction.
### Description :
There are many web applica
Exploit-DB
Adobe Connect 10 - Username Disclosure
exploitdb·2021-02-09
CVE-2023-22232 Adobe Connect 10 - Username Disclosure
Adobe Connect 10 - Username Disclosure
---
# Title: Adobe Connect 10 - Username Disclosure
# Author: h4shur
# date:2021-02-07
# Vendor Homepage: https://www.adobe.com
# Software Link: https://www.adobe.com/products/adobeconnect.html
# Version: 10 and earlier
# Tested on: Windows 10 & Google Chrome
# Category : Web Application Bugs
### Description :
By adding this (/system/help/support) to the end of the desired website address, you can view the username without any filter or obstacle. Sometimes even without a username and password. And by adding (/system/login) to the end of the desired website address, you can access the admin panel without any filters.
### POC :
site.com/system/help/support
### Admin Panel :
site.com/system/login
Nuclei
Adobe Connect < 12.1.5 - Local File Disclosure
nuclei·CVSS 5.3
CVE-2023-22232 [MEDIUM] Adobe Connect < 12.1.5 - Local File Disclosure
Adobe Connect < 12.1.5 - Local File Disclosure
Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction
Template:
id: CVE-2023-22232
info:
name: Adobe Connect < 12.1.5 - Local File Disclosure
author: 0xr2r
severity: medium
description: |
Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does
No writeups or analysis indexed.
http://packetstormsecurity.com/files/171390/Adobe-Connect-11.4.5-12.1.5-Local-File-Disclosure.htmlhttps://helpx.adobe.com/security/products/connect/apsb23-05.htmlhttp://packetstormsecurity.com/files/171390/Adobe-Connect-11.4.5-12.1.5-Local-File-Disclosure.htmlhttps://helpx.adobe.com/security/products/connect/apsb23-05.html
2023-02-17
Published