CVE-2024-27488

Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate the http restful api interface, but the secret is hardcoded by default.
Configurations

No configuration.

History

22 Aug 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-259

08 Apr 2024, 18:48

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de control de acceso incorrecto en las versiones 1.0 a 8.0 de ZLMediaKit, permite a atacantes remotos escalar privilegios y obtener información confidencial. El sistema de aplicación habilita la interfaz API http de forma predeterminada y utiliza el método de parámetro secreto para autenticar la interfaz API restful de http, pero el secreto está codificado de forma predeterminada.

08 Apr 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-08 06:15

Updated : 2024-08-22 17:35


NVD link : CVE-2024-27488

Mitre link : CVE-2024-27488

CVE.ORG link : CVE-2024-27488


JSON object : View

Products Affected

No product.

CWE
CWE-259

Use of Hard-coded Password