CyberRota Analysis
AI-GeneratedThe Xibo digital signage platform for Windows has a vulnerability in the Module::settingsForm that allows authorized users to view super admin-restricted module settings, potentially exposing sensitive information. This issue affects versions prior to 4.4.3 and can be exploited by users with access to the Module View feature, making it crucial for organizations using Xibo to prioritize upgrading to version 4.4.3 to mitigate the risk. If upgrading is not feasible, it is recommended to restrict access privileges for untrusted users.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.3, missing Authorization in Module::settingsForm allows to view (not change) super admin-restricted module settings and leak the full module entity. Exploitation of the vulnerability is possible on behalf of an authorized user who has access to the Module View feature, which are not granted to non-admins as standard. Users should upgrade to version 4.4.3 which fixes this issue. Upgrading to a fixed version is necessary to remediate. Users unable to upgrade should revoke such privileges from users they do not trust.