Vulnerability Description
An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to http://<IP_ADDRESS>:32080/download/<URL_ENCODED_PATH>.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dvdfab | 12 Player | >= 6.2.10, <= 6.2.11 |
| Dvdfab | Playerfab | >= 7.0.0.0, <= 7.0.0.5 |
Related Weaknesses (CWE)
References
- https://www.tenable.com/security/research/tra-2022-07ExploitThird Party Advisory
- https://www.tenable.com/security/research/tra-2022-07ExploitThird Party Advisory
FAQ
What is CVE-2022-25216?
CVE-2022-25216 is a vulnerability with a CVSS score of 7.5 (HIGH). An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has r...
How severe is CVE-2022-25216?
CVE-2022-25216 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-25216?
Check the references section above for vendor advisories and patch information. Affected products include: Dvdfab 12 Player, Dvdfab Playerfab.