CVE-2024-27488: Critical severity ZLMediaKit ZLMediaKit vulnerability
Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate the http restful api interface, but the secret is hardcoded by default.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27488?
CVE-2024-27488 has a high severity rating due to its potential for privilege escalation and information disclosure.
How do I fix CVE-2024-27488?
To fix CVE-2024-27488, upgrade ZLMediaKit to a version above 8.0 where the vulnerability is addressed.
What systems are affected by CVE-2024-27488?
CVE-2024-27488 affects ZLMediaKit versions from 1.0 to 8.0.
Can CVE-2024-27488 be exploited remotely?
Yes, CVE-2024-27488 can be exploited remotely due to improper access control in the application's default settings.
What type of vulnerability is CVE-2024-27488?
CVE-2024-27488 is classified as an Incorrect Access Control vulnerability.