CVE-2024-52054 Vulnerability Details
/
/
/
CVE-2024-52054 Metadata Quick Info
CVE Published: 21/11/2024 |
CVE Updated: 21/11/2024 |
CVE Year: 2024
Source: rapid7 |
Vendor: Wowza |
Product: Streaming Engine
Status : PUBLISHED
CVE-2024-52054 Description
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an XML definition file anywhere on the file system.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-22
CWE Name: CWE-22 Improper Limitation of a Pathname to a Restricted Directory (
Path Traversal
)
Source: Wowza
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description: CWE-23: Relative Path Traversal
Source: NVD (National Vulnerability Database).