cvelist/2022/36xxx/CVE-2022-36243.json
2023-05-30 20:00:38 +00:00

79 lines
2.5 KiB
JSON

{
"CVE_data_meta": {
"ASSIGNER": "support@shopbeat.co.za",
"DATE_PUBLIC": "2023-05-23T09:45:00.000Z",
"ID": "CVE-2022-36243",
"STATE": "PUBLIC",
"TITLE": "Directory Traversal on Shop Beat Services"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "studio",
"version": {
"version_data": [
{
"platform": "arm",
"version_affected": "<",
"version_name": "studio",
"version_value": "3.2.57"
}
]
}
}
]
},
"vendor_name": "Shop Beat"
}
]
}
},
"credit": [
{
"lang": "eng",
"value": "Shop Beat thanks Emirates National Oil Company Limited (ENOC) LLC for the above discovery."
}
],
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server.shopbeat.co.za. Information Exposure Through Directory Listing vulnerability in \"studio\" software of Shop Beat. This issue affects: Shop Beat studio studio versions prior to 3.2.57 on arm."
}
]
},
"generator": {
"engine": "Vulnogram 0.0.9"
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-548 Information Exposure Through Directory Listing"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "MISC",
"url": "https://www.shopbeat.co.za",
"name": "https://www.shopbeat.co.za"
}
]
},
"source": {
"discovery": "INTERNAL"
}
}