CVE Vulnerabilities

CVE-2023-47171

Published: Jan 10, 2024 | Modified: Jan 17, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.

Affected Software

Name Vendor Start Version End Version
Avideo Wwbn 11.6 (including) 11.6 (including)
Avideo Wwbn 15fed957fb (including) 15fed957fb (including)

References