CVE-2022-36243
Summary
| CVE | CVE-2022-36243 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-30 20:15:00 UTC |
| Updated | 2023-06-02 19:44:00 UTC |
| Description | Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server.shopbeat.co.za. Information Exposure Through Directory Listing vulnerability in "studio" software of Shop Beat. This issue affects: Shop Beat studio studio versions prior to 3.2.57 on arm. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Shopbeat | Shop Beat Media Player | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Shop Beat - Giving Your Shop A Beat | MISC | www.shopbeat.co.za | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Shop Beat thanks Emirates National Oil Company Limited (ENOC) LLC for the above discovery.
There are currently no legacy QID mappings associated with this CVE.