First published: Wed Jan 10 2024(Updated: )
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_image` parameter.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
WWBN AVideo | =dev_master_commit_15fed957fb |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49864 has a medium severity rating due to its potential to allow arbitrary file read leading to information disclosure.
To fix CVE-2023-49864, it is recommended to update to a patched version of the WWBN AVideo software that addresses this vulnerability.
CVE-2023-49864 is caused by a flaw in the image upload functionality that allows a specially crafted HTTP request to access arbitrary files.
Users of WWBN AVideo dev master commit 15fed957fb are affected by CVE-2023-49864 and should take measures to secure their installations.
The impact of CVE-2023-49864 includes the potential unauthorized access to sensitive files on the server due to information disclosure.