Description
ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can exploit this to disclose contents of files from local resources.
Problem types
CWE-73 External Control of File Name or Path
Product status
3.0.0
2.1.0.831
1.5.2.822
1.5.2.821
1.5.1.820
Credits
LiquidWorm, Gjoko 'LiquidWorm' Krstic @zeroscience
References
www.exploit-db.com/exploits/48949 (Exploit Database Entry 48949)
www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5599.php (Zero Science Advisory ZSL-2020-5599)
www.vulncheck.com/...yer-directory-traversal-file-disclosure