CyberRota Analysis
AI-GeneratedThe vulnerability in ViewingStatusController allows authenticated users to exploit insecure direct object references, enabling them to read and delete other users' viewing status records. This could lead to unauthorized access to sensitive user data, manipulation of viewing history, and disruption of the "Continue Watching" feature. Organizations using the affected products should prioritize remediation to protect user privacy and maintain the integrity of their services.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete other users' viewing status records. Attackers can enumerate all users' watch progress, delete arbitrary viewing history, and manipulate other users' Continue Watching dashboards by supplying arbitrary primary keys without ownership verification.