CVE Published: 11/03/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: tenable |
Vendor: n/a |
Product: DVDFab 12 Player / PlayerFab Status : PUBLISHED
CVE-2022-25216 Description
An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to http://:32080/download/.