PT-2024-24456 · Shibang Communications · Shibang Communications Ip Network Intercom Broadcasting System
Guo Jiabao
·
Published
2024-04-02
·
Updated
2024-05-17
·
CVE-2024-3218
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Shibang Communications IP Network Intercom Broadcasting System version 1.0
Description
A critical vulnerability has been found in the Shibang Communications IP Network Intercom Broadcasting System. This issue affects an unknown part of the file /php/busyscreenshotpush.php. The manipulation of the
jsondata[callee] and jsondata[imagename] arguments leads to path traversal, allowing an attacker to access files outside the intended directory using '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.Recommendations
For Shibang Communications IP Network Intercom Broadcasting System version 1.0, as a temporary workaround, consider restricting access to the /php/busyscreenshotpush.php file until a patch is available. Additionally, restrict the use of the
jsondata[callee] and jsondata[imagename] arguments in the affected API endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shibang Communications Ip Network Intercom Broadcasting System