CVE-2024-52056 Vulnerability Details
/
/
/
CVE-2024-52056 Metadata Quick Info
CVE Published: 21/11/2024 |
CVE Updated: 21/11/2024 |
CVE Year: 2024
Source: rapid7 |
Vendor: Wowza |
Product: Streaming Engine
Status : PUBLISHED
CVE-2024-52056 Description
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system if the target directory contains an XML definition file.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-22
CWE Name: CWE-22 Improper Limitation of a Pathname to a Restricted Directory (
Path Traversal
)
Source: Wowza
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID: CAPEC-139
CAPEC Description: CAPEC-139 Relative Path Traversal
Source: NVD (National Vulnerability Database).