CVE-2022-25216
DVDFab 12 Player/PlayerFab - Local File Inclusion
Record summary
CVE-2022-25216 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to http://<IP_ADDRESS>:32080/download/<URL_ENCODED_PATH>.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DVDFab 12 Player / PlayerFab | CVE List | 6.2.1.0 - 7.0.0.5 | affected |
Nuclei templates
1ProjectDiscoveryHIGHDVDFab 12 Player/PlayerFab - Local File InclusionCVSS 7.5
DVDFab 12 Player/PlayerFab is susceptible to local file inclusion which allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access.
Impact
The vulnerability allows an attacker to include arbitrary local files, potentially leading to unauthorized access, information disclosure.
Remediation
Apply the latest patch or update from the vendor to fix the vulnerability.
Source: ProjectDiscovery