CVE-2017-5982
Kodi 17.1 - Arbitrary File Disclosure
Record summary
CVE-2017-5982 has a selected CVSS score of 7.5 (high); EIP currently links 2 catalogued exploits and 1 Nuclei template.
Description
Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd.
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBKodi 17.1 - Arbitrary File DisclosureExploitDB exploitby Eric FlokstraNot analyzed1 file
MetasploitKodi 17.0 Local File Inclusion VulnerabilityMetasploit auxiliary PoCby Eric Flokstra +1 moreNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHKodi 17.1 - Local File InclusionCVSS 7.5
Kodi 17.1 is vulnerable to local file inclusion vulnerabilities because of insufficient validation of user input.
Impact
Unauthenticated attackers can read arbitrary files on the system, potentially exposing sensitive information, credentials, and configuration files.
Remediation
Upgrade Kodi to a version that is not affected by the CVE-2017-5982 vulnerability.
Source: ProjectDiscovery