CVE Vulnerabilities

CVE-2022-36243

Exposure of Information Through Directory Listing

Published: May 30, 2023 | Modified: Jan 13, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server.shopbeat.co.za. Information Exposure Through Directory Listing vulnerability in studio software of Shop Beat. This issue affects: Shop Beat studio studio versions prior to 3.2.57 on arm.

Weakness

The product inappropriately exposes a directory listing with an index of all the resources located inside of the directory.

Affected Software

NameVendorStart VersionEnd Version
Shop_beat_media_playerShopbeat2.5.95 (including)3.2.57 (excluding)

Potential Mitigations

References