CVE-2022-28710: Medium severity wwbn avideo vulnerability
Published Aug 22, 2022
·Updated
An information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.
Affected Software
1 affected component
WWBN AVideo=11.6
Event History
Aug 22, 2022
CVE Published
via MITRE·06:22 PM
Data Sourced
via MITRE·06:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-28710?
CVE-2022-28710 is classified as an information disclosure vulnerability.
2
How do I fix CVE-2022-28710?
To fix CVE-2022-28710, upgrade to the latest version of WWBN AVideo that addresses this vulnerability.
3
What are the potential impacts of CVE-2022-28710?
CVE-2022-28710 can lead to arbitrary file read, potentially exposing sensitive information to attackers.
4
What versions of WWBN AVideo are affected by CVE-2022-28710?
CVE-2022-28710 affects WWBN AVideo version 11.6 and dev master commit 3f7c0364.
5
What type of attack vector is associated with CVE-2022-28710?
CVE-2022-28710 can be exploited via a specially-crafted HTTP request.