CVE-2017-20220

Serviio PRO 1.8 contains an improper access control vulnerability in the Configuration REST API that allows unauthenticated attackers to change the mediabrowser login password. Attackers can send specially crafted requests to the REST API endpoints to modify credentials without authentication.
Configurations

No configuration.

History

16 Mar 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:17

Updated : 2026-03-16 14:53


NVD link : CVE-2017-20220

Mitre link : CVE-2017-20220

CVE.ORG link : CVE-2017-20220


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function