Description
An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal.
Exploits (2)
Nuclei Templates (1)
Bazarr < 1.4.3 - Arbitrary File Read
HIGHVERIFIEDby s4e-io
FOFA:
title=="Bazarr" && icon_hash="-1983413099"
Scores
CVSS v3
8.2
EPSS
0.9338
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
bazarr/bazarr
< 1.4.3
Published
Jul 20, 2024
Tracked Since
Feb 18, 2026