Логотип exploitDog
bind:CVE-2024-27488
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-27488

Количество 2

Количество 2

nvd логотип

CVE-2024-27488

почти 2 года назад

Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate the http restful api interface, but the secret is hardcoded by default.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-8vjg-37gr-gvx7

почти 2 года назад

Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate the http restful api interface, but the secret is hardcoded by default.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-27488

Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate the http restful api interface, but the secret is hardcoded by default.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-8vjg-37gr-gvx7

Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate the http restful api interface, but the secret is hardcoded by default.

CVSS3: 9.8
0%
Низкий
почти 2 года назад

Уязвимостей на страницу