PT-2024-33200 · Unknown · Alist-Tvbox

Published

2024-11-21

·

Updated

2024-11-26

·

CVE-2024-48747

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions alist-tvbox version 1.7.1
Description The issue allows a remote attacker to execute arbitrary code via the "/atv-cli" file. This enables the attacker to potentially gain control over the system, allowing for unauthorized actions.
Recommendations For alist-tvbox version 1.7.1, consider restricting access to the "/atv-cli" file as a temporary workaround until a patch is available.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-48747

Affected Products

Alist-Tvbox