NONE · 0

CVE-2024-13991

Huijietong Cloud Video Platform contains a path traversal vulnerability that allows an unauthenticated attacker can supply arbitrary file paths to the `fullPath` parameter of the `/fileDownload?action...

Vulnerability Description

Huijietong Cloud Video Platform contains a path traversal vulnerability that allows an unauthenticated attacker can supply arbitrary file paths to the `fullPath` parameter of the `/fileDownload?action=downloadBackupFile` endpoint and retrieve files from the server filesystem. VulnCheck has observed this vulnerability being exploited in the wild.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-13991?

CVE-2024-13991 is a documented vulnerability. Huijietong Cloud Video Platform contains a path traversal vulnerability that allows an unauthenticated attacker can supply arbitrary file paths to the `fullPath` parameter of the `/fileDownload?action...

How severe is CVE-2024-13991?

CVSS scoring is not yet available for CVE-2024-13991. Check NVD for updates.

Is there a patch for CVE-2024-13991?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.