Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate the http restful api interface, but the secret is hardcoded by default.
References
Configurations
No configuration.
History
22 Aug 2024, 17:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | CWE-259 |
08 Apr 2024, 18:48
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
08 Apr 2024, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-08 06:15
Updated : 2024-08-22 17:35
NVD link : CVE-2024-27488
Mitre link : CVE-2024-27488
CVE.ORG link : CVE-2024-27488
JSON object : View
Products Affected
No product.
CWE
CWE-259
Use of Hard-coded Password