Products

Showing 1 vulnerability on this page

Signals CISA KEV Ransomware Nuclei
ShokoAnime vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Arbitrary file read vulnerability in Shoko Server

ShokoServer is a media server which specializes in organizing anime. In affected versions the `/api/Image/WithPath` endpoint is accessible without authentication and is supposed to return default server images. The endpoint accepts the parameter `serverImagePath`, which is not sanitized in any way before being passed to `System.IO.File.OpenRead`, which results in an arbitrary file read. This issue may lead to an arbitrary file read which is exacerbated in the windows installer which installs the

CWE-22Sep 28, 20231 related artifact
CVSS8.6v3.1EPSS8.15%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX