What the vulnerability does
01Description
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
Explanation of Vulnerability in Simple Terms
Broadcast Live Video versions up to 7.2.4 contain a path traversal vulnerability that allows an attacker to modify files on the server without authentication. The vulnerability exists in how the application handles file paths, enabling an unauthenticated attacker to write or alter files through specially crafted requests. Site administrators should update to a version newer than 7.2.4 to remediate this issue.
What an attacker can do
Write or modify files on the server without needing to log in.
Potential impact on your site
An attacker can alter or inject files on your server, potentially compromising site functionality or injecting malicious content.
Conditions required to exploit
Network access to the application; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities