PT-2024-21918 · Unknown · Zlmediakit

Published

2024-04-07

·

Updated

2024-08-22

·

CVE-2024-27488

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZLMediaKit versions 1.0 through 8.0
Description The issue allows remote attackers to escalate privileges and obtain sensitive information due to an Incorrect Access Control vulnerability. The application system enables the http API interface by default and uses the secret parameter method to authenticate the http restful API interface, but the secret is hardcoded by default.
Recommendations For ZLMediaKit versions 1.0 through 8.0, consider disabling the default http API interface or changing the hardcoded secret parameter to a unique and secure value until a patch is available. Restrict access to the http restful API interface to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-27488

Affected Products

Zlmediakit